Cl0p-Linked Actors Exploit PTC Windchill and FlexPLM in Data Theft Campaign

Red | Attack
Cl0p-Linked Actors Exploit PTC Windchill and FlexPLM in Data Theft Campaign

Summary

Operators suspected of Cl0p affiliation are exploiting internet-exposed PTC Windchill and FlexPLM deployments, chaining a pre-authentication FlexPLM WSDL disclosure with a Windchill login servlet flaw tracked as CVE-2026-12569 for unauthenticated remote code execution, then deploying hex-named JSP web shells and staging engineering and design data for extortion.

Extortion emails referencing PTC Windchill and FlexPLM began July 20, sent to hundreds of staff from compromised accounts; no encryption stage has been reported, so ransomware-tuned controls will not fire. On or about August 12 the group moved from private extortion to public naming, listing roughly forty plus organizations on its leak site, though the substance of each listing remains attacker-claimed. Attribution remains unconfirmed, resting on tradecraft and branded contact infrastructure. Patches for CVE-2026-12569 have been available since June 17, though exploitation may have begun earlier, so retrospective web shell hunting to early June is warranted alongside removal from internet exposure.

CVENameAffected ProductZero-DayCISA KEVPatch
CVE-2026-12569PTC Windchill and FlexPLM Improper Input Validation VulnerabilityPTC Windchill PDMLink, PTC FlexPLMAvailable

Attack Details

01

An active exploitation campaign is targeting internet-exposed PTC Windchill and FlexPLM Product Lifecycle Management deployments. Operators chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, tracked as CVE-2026-12569, achieving unauthenticated remote code execution. Neither credentials nor user interaction are required. Affected builds are not confined to older releases; both PTC Windchill and FlexPLM are impacted across current version lines, so patch status must be confirmed per build rather than assumed from version age.

02

Following exploitation, operators write hex-named JSP web shells into the Windchill login directory, establishing remote command execution on the application server. Filesystem enumeration follows, with engineering and design data staged for extortion; the exfiltration channel remains unspecified in current reporting. The confirmed victim sectors remain manufacturing, automotive, aerospace and retail, where PLM platforms hold the intellectual property defining competitive position. The August leak-site listing extends the apparent footprint into energy, financial technology and healthcare technology, though those additions rest on attacker-claimed entries rather than confirmed intrusions.

03

No encryption stage has been reported. Assessed as data-theft extortion, controls tuned to mass file modification or ransomware execution are unlikely to fire, and an organization can be fully compromised and its design data removed with no conventional ransomware indicator present. Extortion messaging referencing a serious Windchill PDMLink data leak was first observed on July 20, sent to hundreds of users within each affected organization from randomly compromised accounts and carrying the group's latest contact details.

04

Attribution should remain qualified. The actor behind these intrusions is unconfirmed in available reporting, with the Cl0p association resting on tradecraft consistent with prior campaigns against enterprise applications. Branded extortion mail and leak-site infrastructure establish brand usage rather than identity; suspected Cl0p-affiliated remains the defensible position pending tooling or infrastructure overlap.

05

PTC patches for CVE-2026-12569 have been available since June 17, 2026, but patching alone is insufficient. Exploitation is assessed by one source as likely having begun in early June, prior to disclosure, though no published indicator predates June 18. Retrospective web shell hunting should therefore extend to early June alongside removal of these systems from direct internet exposure. Detection should center on the Windchill login path, since legitimate traffic does not POST there at all, a higher-fidelity signal than matching web shell filenames, which change between deployments and now span sixteen-character, six-character and dpr_-prefixed naming conventions.

06

Through late July the group listed no victims and claimed no credit, a silence assessed as characteristic rather than reassuring, matching its pattern across prior file-transfer and ERP campaigns of exploit, exfiltrate, extort privately, then mass-publish. That pattern held. On or about August 12 the group moved to public naming, listing forty plus organizations on its dedicated leak site. The private-to-public transition anticipated at first publication has now occurred; further listings and the release of stolen data are plausible as negotiation windows expire, and victim tracking should continue.


Recommendations

STEP 01
Patch PTC Windchill and FlexPLM

Apply the fixed builds PTC released for CVE-2026-12569, beginning June 17, 2026, across every Windchill PDMLink, FlexPLM and CPS instance. Coverage is not limited to legacy releases: specific 11.1, 11.2, 12.x and 13.x builds are individually listed as affected, and the affected build lists differ between Windchill and FlexPLM. Verify each instance against vendor advisory CS473270.

STEP 02
Remediate the FlexPLM WSDL Disclosure

Treat the pre-authentication information disclosure in the FlexPLM WSDL endpoint as a separate defect requiring its own fixed build, since patching the Windchill RCE alone leaves one half of the exploitation chain intact.

STEP 03
Track the Second Defect Separately

The FlexPLM WSDL information disclosure carries no assigned CVE and is documented only in the vendor advisory, so it will not appear in CVE-driven patch reporting. Verify its fixed build independently.

STEP 04
Hunt for Hex-Named JSP Web Shells

Search the Windchill login directory for files matching /Windchill/login/[0-9a-f]{16}.jsp and compare recovered files against the published SHA-256 hash, treating any unexplained JSP in that path as a compromise indicator.

STEP 05
Alert on the X-windchill-req Header

Configure web server, WAF, and reverse proxy detections for the HTTP request header X-windchill-req: ?x8Fmgow, which is associated with operator interaction with the deployed web shells and has no legitimate application use.

STEP 06
Detect WSDL Reconnaissance Patterns

Build detections for GET requests to /Windchill/rfa/jsp/login/*.jsp?wsdl, giving particular weight to responses of 4045 bytes, to surface pre-exploitation reconnaissance against the FlexPLM WSDL endpoint.

STEP 07
Search for Enumeration Artifacts

Look for a file named flst.txt on Windchill and FlexPLM hosts along with unexplained archives of engineering or design data, both of which indicate filesystem enumeration and staging have already occurred.

STEP 08
Segment the PLM Application Tier

Restrict network paths between the Windchill and FlexPLM application servers and the rest of the environment, including database, directory, and file-share infrastructure, to contain a web shell compromise to the application host.


Indicators of Compromise (IoCs)

TypeValue
SHA25655a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c
IPv4216[.]152[.]148[.]54
216[.]152[.]151[.]204
104[.]243[.]35[.]63
5[.]180[.]41[.]35
23[.]206[.]251[.]247
38[.]60[.]157[.]212
64[.]177[.]69[.]57
64[.]177[.]86[.]200
65[.]20[.]79[.]73
66[.]163[.]122[.]78
74[.]50[.]76[.]146
78[.]128[.]113[.]10
79[.]141[.]163[.]103
81[.]27[.]103[.]18
81[.]27[.]103[.]68
85[.]9[.]211[.]83
87[.]58[.]193[.]42
104[.]194[.]9[.]14
104[.]238[.]145[.]147
104[.]243[.]35[.]0/24
104[.]243[.]35[.]131
111[.]194[.]46[.]135
137[.]184[.]184[.]209
138[.]68[.]51[.]132
144[.]172[.]101[.]13
162[.]243[.]242[.]176
172[.]111[.]38[.]31
185[.]227[.]83[.]236
204[.]194[.]51[.]30
206[.]189[.]199[.]39
209[.]222[.]98[.]44
212[.]147[.]249[.]110
79[.]141[.]160[.]78
Filenameflst.txt
File Path/Windchill/login/[0-9a-f]{16}.jsp
/Windchill/login/dpr_<8 hex>.jsp
HTTP RequestX-windchill-req: ?x8Fmgow
GET /Windchill/rfa/jsp/login/*.jsp?wsdl (response_bytes = 4045)
Recent Confirmed Breaches

Potential MITRE ATT&CK TTPs

T1595.002
ReconnaissanceActive Scanning: Vulnerability Scanning
T1586.002
Resource DevelopmentCompromise Accounts: Email Accounts
T1190
Initial AccessExploit Public-Facing Application
T1059
ExecutionCommand and Scripting Interpreter
T1505.003
PersistenceServer Software Component: Web Shell
T1083
DiscoveryFile and Directory Discovery
T1033
DiscoverySystem Owner/User Discovery
T1074.001
CollectionData Staged: Local Data Staging
T1005
CollectionData from Local System
T1560
CollectionArchive Collected Data
T1071.001
Command and ControlApplication Layer Protocol: Web Protocols
T1657
ImpactFinancial Theft

What Next?

At Hive Pro, it is our mission to detect the most likely threats to your organization and to help you prevent them from happening.

Reduce real exposure. Not just vulnerability volume.