The Clop ransomware group is reportedly targeting internet-exposed PTC Windchill and FlexPLM systems in a new data theft extortion campaign.

Attackers are believed to be exploiting CVE-2026-12569, a critical vulnerability that can allow unauthenticated remote code execution on vulnerable Product Lifecycle Management platforms.

Security researchers observed threat actors deploying JSP webshells after exploiting the flaw. These webshells can give attackers remote control of compromised servers and allow them to steal sensitive product data.

Critical Windchill flaw enables remote code execution

CVE-2026-12569 affects PTC Windchill and FlexPLM, enterprise platforms that companies use to design, track and manage products from initial development through manufacturing.

The vulnerability has a CVSS severity score of 9.3. Researchers described it as an unsafe deserialisation issue that enables attackers to run arbitrary code without authentication.

While the actor behind the intrusions has not been conclusively identified, the observed tactics resemble earlier Clop ransomware campaigns against enterprise applications and high-value data repositories.

Organisations have also begun receiving extortion emails from support@cryptohox.com, an address reportedly linked to Clop operations. The group often changes contact addresses before launching a new extortion campaign.

Agencies warn customers to patch vulnerable systems

PTC started releasing security updates for CVE-2026-12569 on 17 June. It also issued private remediation guidance and urged customers to review their environments for indicators of compromise.

On 26 June, PTC warned customers about heightened threat activity. The US Cybersecurity and Infrastructure Security Agency then added the flaw to its Known Exploited Vulnerabilities catalogue.

CISA ordered US federal agencies to secure affected Windchill and FlexPLM instances within three days.

German authorities also reportedly contacted PTC customers directly and urged them to apply security updates as quickly as possible.

How organisations can reduce risk

Security researchers advise organisations to patch Windchill and FlexPLM systems immediately. Where possible, businesses should also place these systems behind a VPN or trusted access gateway rather than expose them directly to the internet.

If compromise is suspected, organisations should isolate the affected server, preserve forensic evidence and rotate potentially exposed credentials before restoring services.

Windchill and FlexPLM are widely used by engineering, manufacturing, quality and supply-chain teams. Their customer base includes organisations in aerospace, defence, automotive, heavy machinery, retail and medical technology.

PTC says its products serve more than 30,000 customers worldwide, including more than 1,500 brand and retail customers using FlexPLM.

Clop continues data theft extortion strategy

Clop has a long record of targeting enterprise platforms to steal sensitive information. Previous campaigns have exploited Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U, Cleo and MOVEit Transfer.

More recently, the group exploited an Oracle E-Business Suite zero-day flaw to steal files from organisations across several sectors.

After stealing data, Clop typically pressures victims to pay by threatening to publish the files on its dark-web leak site. The US Department of State offers a reward of up to $10 million for information linking the group’s attacks to a foreign government.


0 responses to “Clop Ransomware Targets Windchill and FlexPLM Systems”