threat-intel
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
High
Summary
A sophisticated, custom-built web shell, specifically designed for PTC Windchill and FlexPLM, has been deployed by the Clop ransomware gang. This web shell is capable of decrypting credentials, mapping sensitive data, and running attacker-supplied code, offering a complete toolkit for data theft and post-exploitation activity. The tool leverages a critical vulnerability (CVE-2026-12569) and represents a significant escalation in Clop's extortion tactics, potentially leading to enterprise-wide credential compromise and data exfiltration.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
