Clop-linked PTC Windchill and FlexPLM JSP web shell implant
Malware Activity
Summary
Hide ▲
Show ▼
A JSP web shell has been deployed on PTC Windchill and FlexPLM servers after CVE-2026-12569 exploitation, giving attackers credential theft, vault mapping, and in-memory code execution inside enterprise PLM systems. The implant functions as a backdoor for remote access and can support lateral movement, ransomware, and persistence. It is tailored to the application’s APIs, database schema, keystore, and file-vault structure, which makes the activity harder to detect.
Related Happenings
Clop Internet-exposed Windchill and FlexPLM data theft extortion campaign
Campaign
H score55
First: 24.07.2026 10:36
Last: 24.07.2026 10:36
Sources 1
How related:
An advisory released by Ransom-ISAC along with eCrime.ch and Defused last month attributed the malicious activity to the Clop (aka Cl0p) ransomware operation, with the threat actor dropping JSP web shells against susceptible systems.
About this happening:
The Clop/Cl0p campaign against PTC Windchill and FlexPLM now includes a bespoke JSP web shell tied to CVE-2026-12569. ReliaQuest said the implant is built to dec...
Clop Internet-exposed Windchill and FlexPLM data theft extortion campaign
CampaignHow related: An advisory released by Ransom-ISAC along with eCrime.ch and Defused last month attributed the malicious activity to the Clop (aka Cl0p) ransomware operation, with the threat actor dropping JSP web shells against susceptible systems.
About this happening: The Clop/Cl0p campaign against PTC Windchill and FlexPLM now includes a bespoke JSP web shell tied to CVE-2026-12569. ReliaQuest said the implant is built to dec...
Latest development: 18.08.2026 20:29
A custom Java web shell designed for PTC Windchill and FlexPLM servers was likely deployed in recent data theft attacks exploiting CVE-2026-12569, and it includes built-in features to decrypt credentials, enumerate file repositories, and steal files. The implant uses X-windchill-req control messages, imports Windchill-specific classes such as MethodContext, WTConnection, and WTKeyStoreUtil, and appears to be an application-specific evolution of Clop's mass-exploitation playbook.
PTC Windchill PDMlink and PTC FlexPLM actively exploited RCE (CVE-2026-12569)
Vulnerability
H score43
First: 26.06.2026 15:31
Last: 26.06.2026 15:31
Sources 1
How related:
The web shell is deployed following the weaponization of CVE-2026-12569 (CVSS score: 9.3), which relates to a case of improper input validation that could allow an attacker to execute arbitrary code by sending a malicious request to the network.
About this happening:
CVE-2026-12569 is a critical vulnerability in PTC Windchill and PTC FlexPLM that has been actively exploited for unauthenticated remote code execution and...
PTC Windchill PDMlink and PTC FlexPLM actively exploited RCE (CVE-2026-12569)
VulnerabilityHow related: The web shell is deployed following the weaponization of CVE-2026-12569 (CVSS score: 9.3), which relates to a case of improper input validation that could allow an attacker to execute arbitrary code by sending a malicious request to the network.
About this happening: CVE-2026-12569 is a critical vulnerability in PTC Windchill and PTC FlexPLM that has been actively exploited for unauthenticated remote code execution and...
Latest development: 17.08.2026 14:25
GE, Philips, and Shell are investigating Clop claims that their systems were breached and data stolen in attacks tied to CVE-2026-12569 against Internet-exposed PTC Windchill and PTC FlexPLM instances. Philips says it identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data and that customer environments were not impacted, while Clop claims it stole backups, project plans, photos of facilities, drawings, diagrams, blueprints, and other sensitive data.
CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM
Public Sector Action
H score46
First: 26.06.2026 15:31
Last: 26.06.2026 15:31
Sources 1
About this happening:
CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...
CISA adds CVE-2026-12569 to KEV for PTC Windchill and FlexPLM
Public Sector ActionAbout this happening: CISA added CVE-2026-12569 to the KEV catalog after finding active exploitation of PTC Windchill PDMlink and PTC FlexPLM, elevating the flaw to a federal remedi...
Timeline
-
19.08.2026 08:39 2 articles · 5h ago
Bespoke JSP web shell targets PTC Windchill and FlexPLM servers
Initial DisclosureReliaQuest described a bespoke JSP web shell on PTC Windchill and FlexPLM servers after exploitation of CVE-2026-12569. The implant is tailored to the PLM software and can decrypt Windchill keystore credentials, map engineering vault data, and load attacker-supplied Java bytecode in memory for remote access, lateral movement, persistence, or ransomware.
Show sources
- Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data — thehackernews.com — 19.08.2026 08:39
- Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data — thehackernews.com — 19.08.2026 08:39