Clop Ransomware – Data Theft Attacks

Overview

The Clop ransomware gang (Cl0p) has launched a new data theft extortion campaign targeting PTC Windchill and FlexPLM instances exposed to the internet. Exploiting a critical vulnerability (CVE‑2026‑12569), attackers are deploying JSP webshells to exfiltrate sensitive product lifecycle data from compromised enterprise platforms.

Technical Details

  • Vulnerability: CVE‑2026‑12569 — improper input validation leading to unsafe deserialization.
  • Severity: CVSS 9.3 — allows unauthenticated remote code execution.
  • Attack method:
    • Deploy JSP webshells for remote command execution.
    • Exfiltrate sensitive product data from PLM systems.
  • Victim communication: Extortion emails sent from support@cryptohox.com, a new address linked to Clop’s campaigns.

Impacted Platforms

  • PTC Windchill — enterprise PLM software used for product design and lifecycle management.
  • PTC FlexPLM — widely adopted in retail and brand industries for supply chain and product tracking.
  • Customers: Over 30,000 organizations globally, including 1,500 retail and brand customers.
  • Industries at risk: Aerospace, defense, automotive, heavy machinery, retail, and medtech.

Global Response

  • PTC patches released on June 17, 2026, with remediation guidance.
  • CISA added CVE‑2026‑12569 to its Known Exploited Vulnerabilities catalog, mandating U.S. federal agencies to patch within three days.
  • German BSI issued emergency alerts, contacting PTC customers overnight to enforce immediate patching.
  • Similar urgency was seen earlier in March with CVE‑2026‑4681, another Windchill/FlexPLM flaw.

Defensive Recommendations

ReliaQuest and authorities advise:

  • Patch Windchill and FlexPLM immediately to version with CVE‑2026‑12569 fix.
  • Place systems behind VPNs or trusted access gateways.
  • Isolate compromised servers and collect forensic artifacts.
  • Rotate exposed credentials before restoring service.
  • Monitor for IOCs linked to JSP webshell deployment.

Clop’s Track Record

Clop has a long history of exploiting enterprise platforms:

  • Accellion FTA, GoAnywhere MFT, SolarWinds Serv‑U FTP, Cleo, and MOVEit Transfer — MOVEit alone impacted over 2,770 organizations worldwide.
  • Oracle EBS zero‑day (2025) — victims included Harvard University, The Washington Post, Logitech, Estée Lauder, Korean Air, and American Airlines subsidiary Envoy Air.
  • Data exfiltration is followed by publication on Clop’s dark web leak site, often distributed via Torrent if ransom demands are refused.
  • The U.S. Department of State now offers a $10 million reward for information linking Clop’s attacks to foreign governments.

Expert in the Cloud Insight

Clop’s campaign against Windchill and FlexPLM underscores the strategic targeting of enterprise PLM systems — repositories of intellectual property, supply chain data, and product designs. For organizations, the lesson is clear: patch fast, restrict exposure, and treat PLM platforms as high‑value assets requiring layered defenses.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.