Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Cl0p Hackers Target Windchill Servers for Data Theft

Cl0p Hackers Target Windchill Servers for Data Theft

Posted on July 24, 2026 By CWS

Ransomware Attacks Exploit Windchill Vulnerabilities

Cl0p ransomware affiliates have been exploiting vulnerabilities in PTC Windchill and FlexPLM servers to steal sensitive engineering designs and product data. This ongoing campaign leverages software flaws to gain unauthorized access, enabling attackers to install hidden access points and exfiltrate critical files before demanding ransom.

Targeted Industries and Double-Extortion Tactics

Industries including manufacturing, automotive, aerospace, and retail are particularly vulnerable due to the critical nature of the data stored in Windchill systems. Cl0p attackers employ a double-extortion strategy, threatening to leak stolen data even if victims can restore systems from backups. This tactic puts additional pressure on organizations to meet ransom demands.

Ransom-ISAC, in collaboration with eCrime.ch and DEFUSED, has been tracking these exploitations, warning that unpatched servers facing the internet are the primary entry points for these attacks. The Cl0p group, also known by aliases such as Graceful Spider and FIN11, has been linked to this malicious activity.

Technical Exploits and Vulnerability Details

The attack chain begins with an information disclosure vulnerability in the FlexPLM WSDL endpoint, followed by exploiting a flaw in the Windchill login servlet. This combination allows attackers to execute code remotely without authentication, gaining a foothold on the server.

A critical vulnerability, identified as CVE-2026-12569, is a deserialization flaw with a CVSS score of 9.8. It affects specific versions of PTC Windchill PDMLink and FlexPLM. Disclosed on June 17, CISA added this to its catalog of known exploited vulnerabilities by June 25. Attackers use this vulnerability to deploy webshells, inspect server files, and prepare engineering data for theft.

Impact and Mitigation Strategies

The Cl0p group’s campaigns, such as this one involving Windchill, highlight the ease with which an exposed application can lead to significant data breaches and public extortion. Organizations relying on Windchill for managing sensitive design documents must remain vigilant against such threats.

Ransom-ISAC reported that from July 20, emails with alarming subject lines were sent to employees of affected organizations, spreading awareness internally and pressuring executive and response teams. This tactic mirrors previous campaigns and emphasizes the need for organizations to verify claims and protect employees from follow-on threats.

Immediate actions include securing Windchill and FlexPLM servers, checking for unexpected activity, and reviewing access logs. Monitoring CISA alerts can help prioritize patching efforts for known vulnerabilities.

Future Outlook

This case underscores the dangers of unauthenticated code-execution flaws in business-critical systems. Organizations must act swiftly to identify and patch vulnerabilities to prevent data theft incidents. Continuous monitoring and applying security updates remain key to safeguarding sensitive information.

Cyber Security News Tags:Aerospace, Automotive, CISA, Cl0p, CVE-2026-12569, Cybersecurity, data theft, Extortion, FlexPLM, product design, Ransom-ISAC, Ransomware, Retail, Vulnerabilities, Windchill

Post navigation

Previous Post: BlueNoroff Targets Crypto Wallets via Phishing on Zoom
Next Post: Golden Chickens Unveils New Malware Threats

Related Posts

Windows 11 25H2 Update Preview Released, What’s New? Windows 11 25H2 Update Preview Released, What’s New? Cyber Security News
SonicWall Releases Firmware Update to Remove Rootkit Malware ‘OVERSTEP’ from SMA Devices SonicWall Releases Firmware Update to Remove Rootkit Malware ‘OVERSTEP’ from SMA Devices Cyber Security News
PupkinStealer Attacks Windows System to Steal Login Credentials & Desktop Files PupkinStealer Attacks Windows System to Steal Login Credentials & Desktop Files Cyber Security News
FortiOS SSL-VPN Vulnerability Let Attackers Access full SSL-VPN settings FortiOS SSL-VPN Vulnerability Let Attackers Access full SSL-VPN settings Cyber Security News
Herodotus Android Banking Malware Takes Full Control Of Device Evading Antivirus Herodotus Android Banking Malware Takes Full Control Of Device Evading Antivirus Cyber Security News
Gonjeshke Darande Threat Actors Pose as Hacktivist Infiltrated Iranian Crypto Exchange Gonjeshke Darande Threat Actors Pose as Hacktivist Infiltrated Iranian Crypto Exchange Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Ends Unwanted Ads in Windows 11
  • Golden Chickens Unveils New Malware Threats
  • Cl0p Hackers Target Windchill Servers for Data Theft
  • BlueNoroff Targets Crypto Wallets via Phishing on Zoom
  • ChonkyChicken Malware Targets Chrome Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Ends Unwanted Ads in Windows 11
  • Golden Chickens Unveils New Malware Threats
  • Cl0p Hackers Target Windchill Servers for Data Theft
  • BlueNoroff Targets Crypto Wallets via Phishing on Zoom
  • ChonkyChicken Malware Targets Chrome Credentials

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark