Overview
The Clop ransomware gang (Cl0p) has launched a new data theft extortion campaign targeting PTC Windchill and FlexPLM instances exposed to the internet. Exploiting a critical vulnerability (CVE‑2026‑12569), attackers are deploying JSP webshells to exfiltrate sensitive product lifecycle data from compromised enterprise platforms.
Technical Details
- Vulnerability: CVE‑2026‑12569 — improper input validation leading to unsafe deserialization.
- Severity: CVSS 9.3 — allows unauthenticated remote code execution.
- Attack method:
- Deploy JSP webshells for remote command execution.
- Exfiltrate sensitive product data from PLM systems.
- Victim communication: Extortion emails sent from support@cryptohox.com, a new address linked to Clop’s campaigns.
Impacted Platforms
- PTC Windchill — enterprise PLM software used for product design and lifecycle management.
- PTC FlexPLM — widely adopted in retail and brand industries for supply chain and product tracking.
- Customers: Over 30,000 organizations globally, including 1,500 retail and brand customers.
- Industries at risk: Aerospace, defense, automotive, heavy machinery, retail, and medtech.
Global Response
- PTC patches released on June 17, 2026, with remediation guidance.
- CISA added CVE‑2026‑12569 to its Known Exploited Vulnerabilities catalog, mandating U.S. federal agencies to patch within three days.
- German BSI issued emergency alerts, contacting PTC customers overnight to enforce immediate patching.
- Similar urgency was seen earlier in March with CVE‑2026‑4681, another Windchill/FlexPLM flaw.
Defensive Recommendations
ReliaQuest and authorities advise:
- Patch Windchill and FlexPLM immediately to version with CVE‑2026‑12569 fix.
- Place systems behind VPNs or trusted access gateways.
- Isolate compromised servers and collect forensic artifacts.
- Rotate exposed credentials before restoring service.
- Monitor for IOCs linked to JSP webshell deployment.
Clop’s Track Record
Clop has a long history of exploiting enterprise platforms:
- Accellion FTA, GoAnywhere MFT, SolarWinds Serv‑U FTP, Cleo, and MOVEit Transfer — MOVEit alone impacted over 2,770 organizations worldwide.
- Oracle EBS zero‑day (2025) — victims included Harvard University, The Washington Post, Logitech, Estée Lauder, Korean Air, and American Airlines subsidiary Envoy Air.
- Data exfiltration is followed by publication on Clop’s dark web leak site, often distributed via Torrent if ransom demands are refused.
- The U.S. Department of State now offers a $10 million reward for information linking Clop’s attacks to foreign governments.
Expert in the Cloud Insight
Clop’s campaign against Windchill and FlexPLM underscores the strategic targeting of enterprise PLM systems — repositories of intellectual property, supply chain data, and product designs. For organizations, the lesson is clear: patch fast, restrict exposure, and treat PLM platforms as high‑value assets requiring layered defenses.
Leave a Reply