The Clop ransomware gang is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign. According to cybersecurity company ReliaQuest, Clop operators have been deploying JSP webshells that allow them to exfiltrate sensitive data from targeted companies' compromised PLM platforms.
Exploitation of CVE-2026-12569
Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances. This vulnerability has a CVSS score of 9.3, indicating a high level of severity.
Attack Vector
ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, enabling unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration. The actor behind these attacks remains unconfirmed, however, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories.
The Ransomware Information Sharing and Analysis Centre (Ransom-ISAC) has also confirmed Clop's Windchill and FlexPLM attacks, noting that the gang is using previously compromised email accounts to send extortion messages to multiple employees of targeted organizations.
Extortion Tactics
Clop's extortion emails appear to originate from randomly compromised accounts, are sent to hundreds of users within an impacted organization, and include Cl0p's latest contact information. This extortion approach is consistent with what was observed with the Oracle EBS campaign last year, except for the use of new email addresses.
PTC Response
PTC began releasing security patches for the CVE-2026-12569 flaw on June 17 and released remediation guidance in a private advisory, urging customers to review their environments for indicators of compromise (IOCs). The Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered U.S. federal agencies to secure their PTC Windchill and FlexPLM instances within three days.
German authorities also took emergency action, with the Federal Office for Information Security (BSI) emailing and calling PTC customers in the middle of the night and warning them to patch their systems as quickly as possible.
Recommendations
ReliaQuest advised PTC customers to patch Windchill and FlexPLM systems and place them behind VPNs or trusted access gateways if possible. Additionally, if they suspect compromise, they should isolate the affected servers, collect forensic artifacts, and rotate any exposed credentials before restoring service.
PTC Windchill and PTC FlexPLM are enterprise software platforms used to track, design, and manage products from original idea to final manufacturing. The two PLM systems are widely popular among engineering, manufacturing, quality, and supply chain teams across high-profile companies in the aerospace, defense, automotive, heavy machinery, retail, and medtech sectors.
Clop's History of Attacks
Clop has a long history of breaching enterprise platforms in data theft attacks, with previous campaigns targeting Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer file-sharing servers. The gang has also exploited an Oracle EBS zero-day flaw to steal sensitive files from many organizations since early August 2025.
The U.S. Department of State now offers a $10 million reward for information that could link this cybercrime gang's attacks to a foreign government.
Source: BleepingComputer