{"id":2010,"date":"2026-07-25T16:02:00","date_gmt":"2026-07-25T16:02:00","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2010"},"modified":"2026-07-25T16:02:00","modified_gmt":"2026-07-25T16:02:00","slug":"cl0p-affiliates-target-internet-exposed-ptc-windchill-and-flexplm-with-unauthenticated-rce","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2010","title":{"rendered":"Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 25, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/\u00a0Ransomware<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiIGAlXgFCqm8atTe__HpWBiCWISmrPOazxOVBMF-_YNrP2goBbW_4PSwGzw1Ndyue4qrnQnqrQyAR4DTaAdaiJPlVUZi7M_iceb4fqofWK0sGRLO9CHnj0lngtxdlC-tKqrppqFaKIkct2vOtGn_o5kbNa4fj-dutt8PMjiO5TVBw895aLg0TOJb8TKKtv\/s1700-e365\/cyberattack.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.<\/p>\n<p>\u00abAttackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling unauthenticated remote code execution and deployment of hex-named JSP web shells under \/Windchill\/login\/,\u00bb according to a <a href=\"https:\/\/ransom-isac.org\/blog\/clop-windchill-flexplm-exploitation\/\" target=\"_blank\">new coordinated advisory<\/a> released by Ransom-ISAC along with eCrime.ch and DEFUSED.<\/p>\n<p>Upon gaining an initial foothold, the attackers have been found to conduct file system enumeration, stage engineering\/design data, and ultimately carry out double extortion data theft. Targets of the campaign include manufacturing, automotive, aerospace, and retail sectors.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>It&#8217;s suspected that threat actors are exploiting CVE-2026-12569 (CVSS score: 9.3), a critical security flaw in PTC Windmill that was added to the U.S. Cybersecurity and Infrastructure Security Agency&#8217;s (CISA) Known Exploited Vulnerabilities (KEV) catalog late last month.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>In an advisory, PTC warned customers that it had \u00abreceived continued reports of heightened threat activity,\u00bb adding that unknown attackers are exploiting the vulnerability to deploy JSP web shells against susceptible systems.<\/p>\n<p>\u00abIn the observed intrusions, this RCE is chained with a separate pre-authentication information-disclosure defect in the FlexPLM WSDL endpoint (CVSS v3.1 7.5) to enable unauthenticated exploitation,\u00bb researchers Brandon Parsons, Corsin Camichel, and Simo Kohonen said.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg9dZ5B11XJlJI6oMNpf8I9ElyXWaUM247KIe3hyphenhyphenS2QYRblxjZpmf7NNsmo4mBeEIK4KsaalynHmyDSZ-l7d4bQjJ_YuaqhHYhwUgvg4MpLofVUlUy7Sl2AGMtkQRWBRA9Ep_fi6wYMs9j03sL9oMKCSbsG1SULGvxWhCsr4Mf2jq0D7yOIdWormoiR-8D1\/s1700-e365\/data.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg9dZ5B11XJlJI6oMNpf8I9ElyXWaUM247KIe3hyphenhyphenS2QYRblxjZpmf7NNsmo4mBeEIK4KsaalynHmyDSZ-l7d4bQjJ_YuaqhHYhwUgvg4MpLofVUlUy7Sl2AGMtkQRWBRA9Ep_fi6wYMs9j03sL9oMKCSbsG1SULGvxWhCsr4Mf2jq0D7yOIdWormoiR-8D1\/s1700-e365\/data.png\" alt=\"\" border=\"0\" data-original-height=\"604\" data-original-width=\"1001\"\/><\/a><\/div>\n<p>Ransom-ISAC has shared four IP addresses as indicators of compromise (IoCs), all of which match those shared by PTC &#8211;<\/p>\n<ul>\n<li>216.152.148.54<\/li>\n<li>216.152.151.204<\/li>\n<li>104.243.35.63<\/li>\n<li>5.180.41.35<\/li>\n<\/ul>\n<p>The extortion emails appear to originate from previously compromised accounts and are sent to hundreds of users within an impacted organization, along with ways to contact the Cl0p ransomware crew.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thn.news\/sygnia-webinar\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjnP2BIJTKZ31v-Y_pyvFqC1s6LD-Bo8UNy3UHgqojpVezgaGWw5-sPe5uRK0dfSm3gmDvoKCdHoJnGx1BiTP6Y0qit7D7TCZU_LckTDpdu9eeyuelmJKndEkOxZP6oNPwzguLBCTkAnNkIEvSYaWamKLqYLrJPjnea1V_lz7UcfQkavBo2g3OEGoLyz7mD\/s728-e100\/sygnia-d-4.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>In a separate post on X, ReliaQuest said it observed threat actors actively exploiting CVE-2026-12569 to facilitate \u00abunauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration.\u00bb<\/p>\n<p>\u00abThe actor behind these attacks remains unconfirmed. However, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories,\u00bb it <a href=\"https:\/\/x.com\/ReliaQuestTR\/status\/2079963221365055890\" target=\"_blank\">added<\/a>.<\/p>\n<p>The Cl0p gang has a storied history of going after security flaws in widely-used enterprise products to break into target organizations for data theft and extortion attacks. Previous campaigns mounted by the group have weaponized file transfer appliances, including those from Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer, as well as a vulnerability in Oracle E-Business Suite.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 25, 2026Vulnerability \/\u00a0Ransomware Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2011,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[2724,2723,2725,1113,2212,316,492,725,2213],"class_list":["post-2010","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-affiliates","tag-cl0p","tag-flexplm","tag-internetexposed","tag-ptc","tag-rce","tag-target","tag-unauthenticated","tag-windchill"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2010","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2010"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2010\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2011"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2010"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2010"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2010"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}