Cl0p-Linked Actors Exploit PTC Windchill and FlexPLM in Data Theft Campaign

Red | Attack
Download PDF
Cl0p-Linked Actors Exploit PTC Windchill and FlexPLM in Data Theft Campaign | CVE-2026-12569
Threat Advisory • Attack Report

Cl0p-Linked Actors Exploit PTC Windchill and FlexPLM in Data Theft Campaign

Suspected Cl0p-affiliated operators are chaining a FlexPLM WSDL disclosure with the Windchill login servlet flaw CVE-2026-12569 to plant JSP web shells, steal engineering data, and run mass extortion emails against Manufacturing, Automotive, Aerospace, and Retail organizations.

Admiralty Code: A2 TA Number: TA2026214 Data-Theft Extortion — No Encryption Observed
Date of Publication
July 28, 2026
First Seen
Early June 2026
Targeted Regions
Worldwide
Targeted Platforms
Java Application Server Tier
Targeted Products
PTC Windchill PDMLink, PTC FlexPLM
Targeted Industries
Manufacturing, Automotive, Aerospace, Retail
Malware
JSP Web Shell (unnamed)
Threat Actor
Suspected Cl0p Affiliate
CVE ID
CVE-2026-12569

Summary

Operators suspected of Cl0p affiliation are exploiting internet-exposed PTC Windchill and FlexPLM deployments, chaining a pre-authentication FlexPLM WSDL disclosure with a Windchill login servlet flaw tracked as CVE-2026-12569 for unauthenticated remote code execution, then deploying hex-named JSP web shells and staging engineering and design data for extortion. Extortion emails began 20 July, sent to hundreds of staff from compromised accounts; no encryption stage has been reported, so ransomware-tuned controls will not fire. Attribution remains unconfirmed, resting on tradecraft and branded contact infrastructure. Patches have been available since 17 June, though exploitation may have begun earlier, so retrospective web shell hunting to early June is warranted alongside removal from internet exposure.

CVENameAffected Product
CVE-2026-12569PTC Windchill and FlexPLM Improper Input Validation VulnerabilityPTC Windchill PDMLink, PTC FlexPLM

Attack Details

#1 — Exploit Chain

An active exploitation campaign is targeting internet-exposed PTC Windchill and FlexPLM Product Lifecycle Management deployments. Operators chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, tracked as CVE-2026-12569, achieving unauthenticated remote code execution. Neither credentials nor user interaction are required. Affected builds are not confined to older releases, both products are impacted across current version lines, so patch status must be confirmed per build rather than assumed from version age.

#2 — Web Shell Deployment and Data Staging

Following exploitation, operators write hex-named JSP web shells into the Windchill login directory, establishing remote command execution on the application server. Filesystem enumeration follows, with engineering and design data staged for extortion; the exfiltration channel remains unspecified in current reporting. Confirmed victim sectors are manufacturing, automotive, aerospace and retail, where PLM platforms hold the intellectual property defining competitive position.

#3 — Data-Theft Extortion, No Encryption

No encryption stage has been reported. Assessed as data-theft extortion, controls tuned to mass file modification or ransomware execution are unlikely to fire, and an organization can be fully compromised and its design data removed with no conventional ransomware indicator present. Extortion messaging referencing a serious Windchill PDMLink data leak was first observed on 20 July, sent to hundreds of users within each affected organization from randomly compromised accounts and carrying the group's latest contact details.

#4 — Attribution

Attribution should remain qualified. The actor behind these intrusions is unconfirmed in available reporting, with the Cl0p association resting on tradecraft consistent with prior campaigns against enterprise applications. Branded extortion mail and leak-site infrastructure establish brand usage rather than identity; suspected Cl0p-affiliated remains the defensible position pending tooling or infrastructure overlap.

#5 — Patch Timeline and Detection Focus

PTC patches have been available since 17 June 2026, but patching alone is insufficient. Exploitation is assessed by one source as likely having begun in early June, prior to disclosure, though no published indicator predates 18 June. Retrospective web shell hunting should therefore extend to early June alongside removal of these systems from direct internet exposure. Detection should center on the Windchill login path, since legitimate traffic does not POST there at all, a higher-fidelity signal than matching web shell filenames, which change between deployments.

#6 — Outlook

As of 28 July no victims of this campaign had been listed and no credit publicly claimed. The silence is assessed as characteristic rather than reassuring: the group's pattern across prior file-transfer and ERP campaigns is exploit, exfiltrate, extort privately, then mass-publish. A naming wave in the August–September window is plausible; pre-staging victim tracking now is warranted.


Recommendations

01
Patch PTC Windchill and FlexPLM
Apply the fixed builds PTC released for CVE-2026-12569, beginning June 17, 2026, across every Windchill PDMLink, FlexPLM and CPS instance. Coverage is not limited to legacy releases: alongside all builds at or below 11.0 M030, specific 11.1, 11.2, 12.x and 13.x builds are individually listed as affected. Verify each instance against the exact version table in vendor advisory CS473270.
02
Remediate the FlexPLM WSDL Disclosure
Treat the pre-authentication information disclosure in the FlexPLM WSDL endpoint as a separate defect requiring its own fixed build, since patching the Windchill RCE alone leaves one half of the exploitation chain intact.
03
Track the Second Defect Separately
The FlexPLM WSDL information disclosure carries no assigned CVE and is documented only in the vendor advisory, so it will not appear in CVE-driven patch reporting. Verify its fixed build independently.
04
Hunt for Hex-Named JSP Webshells
Search the Windchill login directory for files matching /Windchill/login/[0-9a-f]{16}.jsp and compare recovered files against the published SHA-256 hash, treating any unexplained JSP in that path as a compromise indicator.
05
Alert on the X-windchill-req Header
Configure web server, WAF, and reverse proxy detections for the HTTP request header X-windchill-req: ?x8Fmgow, which is associated with operator interaction with the deployed webshells and has no legitimate application use.
06
Detect WSDL Reconnaissance Patterns
Build detections for GET requests to /Windchill/rfa/jsp/login/*.jsp?wsdl, giving particular weight to responses of 4045 bytes, to surface pre-exploitation reconnaissance against the FlexPLM WSDL endpoint.
07
Search for Enumeration Artifacts
Look for a file named flst.txt on Windchill and FlexPLM hosts along with unexplained archives of engineering or design data, both of which indicate filesystem enumeration and staging have already occurred.
08
Segment the PLM Application Tier
Restrict network paths between the Windchill and FlexPLM application servers and the rest of the environment, including database, directory, and file-share infrastructure, to contain a webshell compromise to the application host.

Potential MITRE ATT&CK TTPs

T1595
T1595.002
Reconnaissance
Active Scanning — Vulnerability Scanning
T1586
T1586.002
Resource Development
Compromise Accounts — Email Accounts
T1190
Initial Access
Exploit Public-Facing Application
T1059
Execution
Command and Scripting Interpreter
T1505
T1505.003
Persistence
Server Software Component — Web Shell
T1083
Discovery
File and Directory Discovery
T1074
T1074.001
Collection
Data Staged — Local Data Staging
T1071
T1071.001
Command and Control
Application Layer Protocol — Web Protocols
T1657
Impact
Financial Theft

Indicators of Compromise (IOCs)

TypeValue
SHA25655a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c
IPv4216.152.148.54, 216.152.151.204, 104.243.35.63, 5.180.41.35
Filenameflst.txt
File Path/Windchill/login/[0-9a-f]{16}.jsp
HTTP RequestX-windchill-req: ?x8Fmgow, GET /Windchill/rfa/jsp/login/*.jsp?wsdl (response_bytes = 4045)

References & Patch Links