logo

Cl0p Exploits PTC Windchill Zero-Day to Deploy Webshells and Steal Data

ID: fbae7bf7-e16f-5ab9-8aa5-0cd1ad5f0bd1

STIX ID: report--fbae7bf7-e16f-5ab9-8aa5-0cd1ad5f0bd1

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

Author: Tamilselvan

...
...

Cl0p-affiliated attackers are actively exploiting a critical PTC Windchill/FlexPLM zero-day (CVE-2026-12569, CVSS 9.8) to perform unauthenticated remote code execution against internet-exposed PLM instances, deploy hex-named JSP webshells under /Windchill/login/, enumerate and stage CAD/design repositories, and exfiltrate sensitive engineering data for double-extortion; the advisory includes IOCs (four new IPs, a SHA-256 hash, distinctive HTTP header and webshell naming pattern), detection guidance (log hunting for specific WSDL responses, /Windchill/login/[0-9a-f]{16}.jsp access, X-windchill-req header), and remediation actions aligned with CISA KEV and vendor patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.