news.mlab.sh
Back to the feed
threat-intel

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Critical
Summary

Threat actors linked to the Cl0p ransomware group are exploiting internet-exposed PTC Windchill and FlexPLM deployments to gain unauthenticated remote code execution and steal sensitive data for extortion. The campaign leverages a combination of vulnerabilities, including a critical flaw in Windchill and a separate information disclosure issue in FlexPLM, targeting sectors like manufacturing, automotive, and aerospace.

Threat actors associated with the Cl0p ransomware campaign are actively exploiting vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments to conduct data theft and extortion attacks. The campaign utilizes a chain of attacks, beginning with a pre-authentication information disclosure in the FlexPLM WSDL endpoint (CVSS v3.1 7.5) to enable unauthenticated exploitation, alongside a critical security flaw in PTC Windchill (CVE-2026-12569, CVSS score: 9.3). This allows attackers to deploy JSP web shells under /Windchill/login/ for remote code execution and sensitive product data exfiltration.

The campaign involves conducting file system enumeration, staging engineering/design data, and ultimately carrying out double extortion data theft. Ransom-ISAC has shared four IP addresses as indicators of compromise (IoCs): 216.152.148.54, 216.152.151.204, 104.243.35.63, and 5.180.41.35. The attackers are leveraging previously compromised accounts to send extortion emails to hundreds of users within an impacted organization, providing contact information for the Cl0p ransomware crew.

PTC warned customers about heightened threat activity and the exploitation of CVE-2026-12569. ReliaQuest observed threat actors actively exploiting the vulnerability to facilitate unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration. The Cl0p gang has a history of targeting enterprise applications and high-value data repositories, previously weaponizing file transfer appliances like Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer, and exploiting vulnerabilities in Oracle E-Business Suite.

Read the full article at The Hacker News