Clop Deploys Custom Web Shell in PTC Windchill Extortion Attacks
ID: 980bff9f-7ad3-55e0-ab7c-8684afadba85
STIX ID: report--980bff9f-7ad3-55e0-ab7c-8684afadba85
Feed Name: securityonline.info
ReliaQuest and industry reporting attribute active exploitation of CVE-2026-12569 in PTC Windchill to the Clop extortion group, which deploys a custom Java web shell that decrypts stored credentials, inventories Windchill file vaults for data theft, hides command traffic via custom HTTP headers and GZIP, and supports an in-memory loader for deploying further malware or ransomware; operators should apply vendor patches, hunt for suspicious JSP files, rotate keystore credentials, and enable header logging, response decompression, and TLS inspection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
