Cl0p Exploits PTC Windchill Zero-Day to Deploy Webshells and Steal Data
ID: fbae7bf7-e16f-5ab9-8aa5-0cd1ad5f0bd1
STIX ID: report--fbae7bf7-e16f-5ab9-8aa5-0cd1ad5f0bd1
Feed Name: Cyber Press
Cl0p-affiliated attackers are actively exploiting a critical PTC Windchill/FlexPLM zero-day (CVE-2026-12569, CVSS 9.8) to perform unauthenticated remote code execution against internet-exposed PLM instances, deploy hex-named JSP webshells under /Windchill/login/, enumerate and stage CAD/design repositories, and exfiltrate sensitive engineering data for double-extortion; the advisory includes IOCs (four new IPs, a SHA-256 hash, distinctive HTTP header and webshell naming pattern), detection guidance (log hunting for specific WSDL responses, /Windchill/login/[0-9a-f]{16}.jsp access, X-windchill-req header), and remediation actions aligned with CISA KEV and vendor patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
