Cl0p Ransomware Targets PTC Software
The notorious Cl0p ransomware group, also known by aliases such as Chubby Scorpius and FIN11, has launched a new wave of attacks exploiting vulnerabilities in PTC’s Windchill and FlexPLM applications. These attacks are part of an escalating data extortion campaign targeting industries including manufacturing, automotive, aerospace, and retail.
New Exploits in PTC Windchill and FlexPLM
Threat actors have been exploiting a combination of a pre-authentication vulnerability in the FlexPLM WSDL endpoint and a server-side flaw in the Windchill login servlet. This technique enables them to execute unauthorized remote code and deploy JSP web shells within the Windchill login path. This coordinated advisory by Ransom-ISAC, eCrime.ch, and DEFUSED highlights the severity of the threat.
Upon breaching the systems, attackers engage in file system exploration, staging sensitive engineering and design data, and executing double extortion tactics. This involves not only data theft but also potential threats of releasing the data unless a ransom is paid, significantly impacting targeted sectors.
Critical Vulnerability CVE-2026-12569
The exploitation centers around CVE-2026-12569, a critical flaw in PTC Windchill with a CVSS score of 9.3. This vulnerability was recently added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, underscoring its critical nature. PTC has issued warnings to its customers about increased threat activities exploiting this vulnerability to install JSP web shells.
Security researchers Brandon Parsons, Corsin Camichel, and Simo Kohonen have detailed how this remote code execution (RCE) vulnerability is combined with a separate pre-authentication flaw in FlexPLM, adding another layer of risk for organizations using these software solutions.
Indicators of Compromise and Warnings
Ransom-ISAC has identified four IP addresses as indicators of compromise (IoCs), coinciding with those shared by PTC. These addresses are being used to detect and mitigate potential breaches. The extortion emails used in these attacks often originate from previously compromised accounts, and they are widespread, affecting hundreds of users within affected organizations.
Further analysis by ReliaQuest has confirmed the active exploitation of CVE-2026-12569 by Cl0p actors to execute unauthorized commands and exfiltrate sensitive data. Although the exact identities of the attackers remain undetermined, the methods align with prior Cl0p operations targeting enterprise software vulnerabilities.
Conclusion and Future Outlook
The Cl0p ransomware group continues to pose a significant threat by exploiting vulnerabilities in widely-used enterprise software. The group’s history of targeting security flaws for data theft and extortion emphasizes the need for organizations to strengthen cybersecurity measures and remain vigilant against potential threats. As these attacks evolve, continuous monitoring and prompt vulnerability patching are imperative to safeguard critical data assets.
