logo

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

ID: 0d5976ef-5251-5592-ad30-f719cb888574

STIX ID: report--0d5976ef-5251-5592-ad30-f719cb888574

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-08-19

Date Updated: 2026-08-20

Author: [email protected] (The Hacker News)

...
...

ReliaQuest and other researchers report that the Clop ransomware operation is deploying a bespoke JSP web shell against PTC Windchill and FlexPLM servers via CVE-2026-12569 (CVSS 9.3). The implant is a feature-rich extortion platform that decrypts keystore credentials (including LDAP/administrative secrets), enumerates file vaults, loads attacker Java payloads in memory, and exfiltrates sensitive engineering data, enabling rapid lateral movement, persistence, and large-scale data theft without additional tooling.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.