Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data.
The campaign combines software flaws to gain access without credentials, install hidden server-side access, and remove sensitive files before demanding payment.
The activity places manufacturers, automotive firms, aerospace organizations, and retail apparel companies at particular risk because Windchill systems can hold highly valuable product records.
Attackers use a double-extortion model, allowing them to pressure victims with stolen data even when systems can be recovered from backups.
Analysts at Ransom-ISAC, working with eCrime.ch and DEFUSED, identified active exploitation and warned that unpatched, internet-facing deployments remain the main entry point.
The activity is linked to Cl0p affiliates, an operation also known as Graceful Spider, Chubby Scorpius, FIN11, and Lace Tempest.
Ransom-ISAC said in a report shared with Cyber Security News (CSN) that the intrusions appear to date back to early June and have been followed by mass extortion emails sent through randomly compromised accounts.
The messages force organizations to investigate possible theft quickly while also protecting employees from follow-on phishing and social-engineering attempts.
Cl0p Hackers Exploit Windchill Servers
The attack begins with a pre-authentication information disclosure in the FlexPLM WSDL endpoint, followed by abuse of a weakness in the Windchill login servlet.
Chaining the two flaws gives attackers a way to execute code remotely without a valid account and establish a foothold on the server.
The key vulnerability, CVE-2026-12569, is a critical deserialization flaw with a CVSS score of 9.8 that affects PTC Windchill PDMLink and FlexPLM releases before 11.0 M030. It was disclosed on June 17, while CISA added it to its Known Exploited Vulnerabilities catalog on June 25.
After gaining access, the operators deploy JSP webshells, inspect server files, and stage engineering data for theft.
The incident follows the pattern seen in recent Cl0p ransomware actor campaigns, where an exposed enterprise application can become a direct route to confidential data and public extortion.
This is especially concerning for organizations that use Windchill to manage design documents, product specifications, and development workflows.
A successful breach can expose intellectual property that is difficult to replace and may give competitors or criminal buyers insight into unreleased products.
The attackers did not need to break through an employee mailbox or trick a user into opening a malicious attachment.
Instead, they targeted a public-facing application, underscoring why organizations should continuously identify internet-exposed systems and rapidly apply security updates for high-impact vulnerabilities.
Extortion Campaign Raises Pressure
On July 20, Ransom-ISAC began observing emails with the subject line “Windchill PDMLink module serious data leak” sent to hundreds of employees at affected organizations.
This approach spreads the breach allegation internally and increases pressure on executives and incident-response teams before a victim is named publicly.
The tactic is similar to last year’s Oracle EBS campaign, although the current operation uses new email addresses.
.webp)
Organizations facing such messages should preserve the emails and headers, validate the claim through internal investigation, and remind employees to report suspicious communications, as seen in reported Oracle EBS breach investigations.
The organizations receiving matching emails should hunt for compromise dating back to early June, use published indicators, apply fixed builds, and follow the vendor’s remediation guidance.
Security teams should give immediate priority to externally reachable Windchill and FlexPLM servers, check for unexpected JSP files and unusual outbound activity, and review access logs for the noted reconnaissance request.
Monitoring CISA KEV catalog alerts can also help teams focus patching work on flaws known to be exploited.
The case also highlights the danger of unauthenticated code-execution flaws in business-critical systems.
Similar unauthenticated remote code risks have shown how quickly a server vulnerability can become a broader data-theft incident when patches are delayed.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| IP address | 216.152.148.54 | Newly published C2 indicator |
| IP address | 216.152.151.204 | Newly published C2 indicator |
| IP address | 104.243.35.63 | Newly published C2 indicator |
| IP address | 5.180.41.35 | Newly published C2 indicator |
| SHA-256 | 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c | Published hash indicator |
| HTTP header | X-windchill-req: ?x8Fmgow | Malicious request header |
| Webshell path | Windchill/login/[0-9a-f]{16}.jsp | Hunt path for hex-named JSP webshells |
| File name | flst.txt | File listing artifact |
| Reconnaissance request | GET /Windchill/rfa/jsp/login.jsp?wsdl | Observed pre-attack WSDL request |
| Response size | 40454 bytes | Response size associated with the reconnaissance request |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

