Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
ID: 0d5976ef-5251-5592-ad30-f719cb888574
STIX ID: report--0d5976ef-5251-5592-ad30-f719cb888574
Feed Name: The Hacker News
ReliaQuest and other researchers report that the Clop ransomware operation is deploying a bespoke JSP web shell against PTC Windchill and FlexPLM servers via CVE-2026-12569 (CVSS 9.3). The implant is a feature-rich extortion platform that decrypts keystore credentials (including LDAP/administrative secrets), enumerates file vaults, loads attacker Java payloads in memory, and exfiltrates sensitive engineering data, enabling rapid lateral movement, persistence, and large-scale data theft without additional tooling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
