Cl0p and PTC Windchill: The Custom Implant That Turned Engineering Vaults Into an Extortion Campaign
By Sethu Satheesh · 11 Sept 2026 · 21 min read
Threat Actor: Cl0p (TA505 / FIN11 / Lace Tempest / Graceful Spider) — attributed by Ransom-ISAC and ReliaQuest at high confidence via extortion-email contact addresses and leak-site postings · Target: Organisations running internet-exposed PTC Windchill PDMLink and FlexPLM; 43 named on Cl0p's leak site across manufacturing, aerospace, automotive, energy, medtech, retail and fintech
Source: www.ptc.com
Executive Summary
Between early June and mid-August 2026, the Cl0p extortion group ran a mass data-theft campaign against organisations running PTC Windchill and FlexPLM, the product lifecycle management platforms that hold CAD models, bills of materials, engineering change records and supplier data for a large share of the world's manufacturers. The entry point was CVE-2026-12569, an unauthenticated deserialization flaw in the Windchill login servlet, chained in observed intrusions with a pre-authentication information disclosure in the FlexPLM WSDL endpoint. PTC published remediation on 17 June and confirmed exploitation the next day; CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 25 June with a three-day deadline. Ransom-ISAC assesses the flaw was exploited as a zero-day in early June, before any fix existed.
What distinguishes this campaign from generic web-shell exploitation is the implant. ReliaQuest's analysis of the JSP shell, published 18 August, shows it was written for Windchill specifically: it imports the application's own MethodContext, WTConnection and WTKeyStoreUtil classes, decrypts every credential in the Windchill keystore with a single command, queries the vault database for file names, paths and sizes using Windchill's internal schema, and carries a Java class loader that runs attacker-supplied bytecode in memory. Commands arrive in a custom HTTP header, X-windchill-req, and responses are GZIP-compressed, so the traffic looks like the application's own. This is Cl0p's established pattern, DEWMODE for Accellion in 2021 and LEMURLOOT for MOVEit in 2023, applied to a platform whose contents are blueprints rather than files in transit.
Extortion emails with the subject line "Windchill PDMLink module serious data leak" began reaching hundreds of employees at affected organisations on 20 July. Between 12 and 19 August, Cl0p named 43 organisations on its leak site, among them Shell, Philips, General Electric, Fiserv, Zebra Technologies, Toast, Ingersoll Rand, Mindray and Largan Precision, with claimed data volumes from 1 GB to 8 TB per victim. Philips confirmed a contained intrusion of one server; Shell said it was investigating; Zebra and Toast reported limited impact; GE said it was assessing and was later reported removed from the leak site. No victim has confirmed the volume Cl0p claims, and no data samples have been published.
The vulnerability sits in a pattern that the coverage has not joined up. In March 2026 PTC disclosed CVE-2026-4681, another unauthenticated deserialization RCE in the same products, warning of "credible evidence of an imminent threat by a third-party group"; German federal police visited companies in person at 3:30 in the morning to make them patch. In June, the BSI phoned Windchill administrators at 2:30 AM on the 17th, hours before PTC's public advisory, citing a "partner authority" and a patch dated 15 June. On 20 August, while the extortion wave was in progress, PTC disclosed a third deserialization RCE, CVE-2026-77645, plus an SSRF. Three unauthenticated deserialization flaws in one product in five months is a statement about the product, not about any one of them. PTC has not said how CVE-2026-12569 was discovered, when exploitation began, or how many customers were affected.
Verification of Claims
-
Claim: CVE-2026-12569 is an unauthenticated remote code execution flaw in Windchill PDMLink and FlexPLM caused by deserialization of untrusted data. → Verified → NVD record (CWE-20, CWE-502); PTC Trust Center advisory; CISA KEV entry of 25 June 2026 ("unauthenticated, remote attacker to execute arbitrary code by sending a malicious request").
-
Claim: The flaw was exploited before the patch, as a zero-day. → Assessed, not confirmed → Ransom-ISAC: "most likely exploited … as a zero-day vulnerability in early June 2026." Censys: exploitation suspected "early to mid June." PTC has not stated an exploitation start date. The BSI's 17 June email warned of "impending" attacks, and PTC's 18 June update published six web-shell paths and a C2 address, which implies compromises had already been analysed by then.
-
Claim: The CVSS score is 9.3 / 9.8 / 10.0. → Verified — all three, on different scales → 9.3 is PTC's CVSS 4.0 score, carried by NVD and cited by ReliaQuest. 9.8 is NVD's own CVSS 3.1 score. 10.0 is the CVSS 3.1 figure cited by heise and, for the March flaw, by the BSI. The three are not in conflict; reporting that picks one without saying which scale is incomplete.
-
Claim: A patch existed on 15 June, two days before PTC's public advisory. → Partially verified → The BSI's email of 17 June, reproduced by heise, states "the patch released on 06/15/2026 represents a secured version of the software." PTC's public changelog begins at 2:16 PM ET on 17 June with "remediation steps now available." PTC's eSupport article CS473270 is behind a customer login and may carry the earlier date; ThreatPaper could not view it.
-
Claim: The web shell is custom-built for Windchill and attributable to Cl0p. → Assessed, not confirmed → ReliaQuest, 18 August: "highly likely" Cl0p, on three grounds: extortion-email contact addresses match Cl0p's leak site, the
X-windchill-reqheader matches earlier reporting, and the custom-shell-after-mass-exploit pattern matches DEWMODE and LEMURLOOT. Ransom-ISAC independently encountered the same sample (SHA-256321e1f…98bf) in an incident. No law enforcement attribution has been published. -
Claim: Cl0p listed 43 victims. → Verified as a leak-site count → BleepingComputer, 17 August: "a batch of 43 new victims"; SecurityWeek, 19 August: "over 40"; CPO Magazine: "50+". Ransom-ISAC dates the listings to 14–19 August; BleepingComputer dates the first full names to 12 August. The count is of leak-site entries, not confirmed compromises.
-
Claim: Shell, GE and Philips had data stolen. → Partially verified → Philips (to Reuters): "identified and contained an attempted cybersecurity compromise of a specific enterprise server related to internal data." Shell: "aware of a potential incident … working with our security teams." GE: "working to assess the potential issue." None has confirmed exfiltration or volume. Cl0p claims 89 GB from Shell; that figure is the group's.
-
Claim: Fewer than 100 Windchill instances were exposed to the internet. → Verified as Censys's observation → Censys, 30 July: "fewer than 100 instances … as of June 1"; ~80 on 20 July; 80% in the US; about a quarter behind Akamai. Censys fingerprinting undercounts instances behind CDNs and on non-default paths, which may explain how 43 victims arose from fewer than 100 observed targets.
-
Claim: CISA gave federal agencies three days. → Verified → KEV entry: dateAdded 2026-06-25, dueDate 2026-06-28, knownRansomwareCampaignUse "Known", under BOD 26-04.
-
Claim: This was the second unauthenticated deserialization RCE in Windchill in three months. → Verified → CVE-2026-4681, published to NVD 23 March 2026 (CWE-94, CVSS 4.0 9.3), affecting the same version list; PTC then warned of an "imminent threat by a third-party group." CVE-2026-77645 followed on 20 August (CWE-502, CVSS 4.0 9.2).
-
Claim: The US State Department is offering a $10 million reward for information linking Cl0p to a foreign government. → Superseded in framing → The reward was announced under the Rewards for Justice programme in June 2023 during the MOVEit campaign. It remains open, but it is not a response to this campaign, which is how "now offers" reads in current coverage.
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| 20 March 2026 | PTC | Discloses CVE-2026-4681, unauthenticated deserialization RCE in Windchill and FlexPLM; no patch; warns of "credible evidence of an imminent threat by a third-party group." Recommends blocking the servlet path or disconnecting from the internet. | BleepingComputer, 24 Mar; NVD |
| 22–23 March 2026 | BKA / state police | Officers phone and physically visit German Windchill customers overnight, at 2:45 and 3:30 AM Sunday, to demand patching. Unofficially over 1,000 German companies affected. | heise, 23 Mar |
| Early June 2026 | Cl0p (assessed) | Exploitation of CVE-2026-12569 begins, before any fix. | Ransom-ISAC; Censys |
| 1 June 2026 | Censys | Fewer than 100 Windchill instances observed internet-exposed. | Censys, 30 Jul |
| 15 June 2026 | PTC | Patch date cited in the BSI's warning email. | heise, 19 Jun |
| 17 June 2026, 02:30 CEST | BSI | Phones Windchill administrators; emails follow. Source: "a partner authority within the National IT Situation Center." | heise, 19 Jun |
| 17 June 2026, 14:16 ET | PTC | Trust Center advisory: "Remediation steps now available and should be applied immediately." CVE referenced at 21:28 ET. | PTC changelog |
| 18 June 2026 | PTC; NVD | Patches for 13.0.2, 12.1.2, 12.0.2. First IOC set: C2 5.180.41[.]35, six 16-hex JSP web-shell paths, header X-windchill-req: ?x8Fmgow, hash 55a1eb…a30c, flst.txt. NVD publishes the CVE. |
PTC changelog; NVD |
| 19 June 2026 | PTC | Patches for 11.2.1, 11.1 M020, 11.0 M030, 13.1.1. | PTC changelog |
| 23–25 June 2026 | PTC; CISA | New IOC IPs; "continued reports of heightened threat activity." CISA adds to KEV, due 28 June. | PTC changelog; KEV |
| 1–9 July 2026 | PTC | Further IOC batches; six-hex web-shell naming observed 8 July. | PTC changelog |
| 14 July 2026 | PTC | Consolidated security patches for all supported versions. | PTC changelog |
| 17 July 2026 | Cl0p | New extortion email infrastructure registered. | Censys |
| 20 July 2026 | Cl0p | Extortion emails, subject "Windchill PDMLink module serious data leak," sent to hundreds of employees per victim from compromised third-party accounts. | Ransom-ISAC, 22 Jul |
| 22 July 2026 | Ransom-ISAC | Unified Threat Advisory with eCrime.ch and DEFUSED attributes campaign to Cl0p affiliates. No victims yet listed. | Ransom-ISAC |
| 27 July 2026 | PTC | Expanded IOC set: 28 IPs, dpr_ web-shell naming, 44 MD5 hashes. |
PTC changelog |
| 12–19 August 2026 | Cl0p | 43 organisations named on leak site; partial names first, full names from 12 August. | BleepingComputer; Ransom-ISAC |
| 14 August 2026 | Ransom-ISAC | C2 79.141.160[.]78 and implant hash 321e1f…98bf observed in an active incident. |
Ransom-ISAC |
| 15–17 August 2026 | Shell; Philips; GE | Shell "aware of a potential incident"; Philips confirms contained compromise of one server; GE "assessing." | BleepingComputer, 17 Aug |
| 18 August 2026 | ReliaQuest | Publishes analysis of the custom implant. | ReliaQuest |
| 19 August 2026 | CyberScoop; Ransom-ISAC | Zebra and Toast report limited impact. PTC declines to answer how the flaw was found, when exploitation began, or how many customers were hit. Ransom-ISAC adds structural YARA rule. | CyberScoop; Ransom-ISAC |
| 20 August 2026 | PTC | Discloses CVE-2026-77645 (deserialization RCE, CVSS 4.0 9.2) and CVE-2026-77646 (SSRF, 7.7). | PTC changelog; NVD |
| 26 August 2026 | PTC | Adds IOC 23.95.238[.]5. |
PTC changelog |
Attack Anatomy
Loading diagram...
Stage 1: reconnaissance
PTC's detection guidance includes one pre-attack signature: a GET to /Windchill/rfa/jsp/login/*.jsp?wsdl returning exactly 4,045 bytes. Ransom-ISAC describes this as a pre-authentication information disclosure in the FlexPLM WSDL endpoint, scored CVSS 7.5, which the operators chain with the RCE. The WSDL response presumably confirms product and version before the exploit is sent; PTC has not described what it leaks.
Stage 2: exploitation
CVE-2026-12569 is deserialization of untrusted data reachable without authentication through the Windchill login servlet. PTC's 29 June update refers to "the Java serialization filter related to com.ptc.wpcfg.logic.ExpressionClassMethod," which is the workaround and therefore the likely gadget path. A successful request writes a JSP file into the login directory under <WT_HOME>/codebase/login/. PTC's advisory notes that "legitimate Windchill traffic does not POST to this path," which makes any POST to /Windchill/login/*.jsp a detection.
The web shells were named with 16 lowercase hex characters at first (7c0a0a34c9d8d53b.jsp and five others published on 18 June), then six hex characters from early July, sometimes with ?cmd=whoami appended, then dpr_ plus eight hex characters by late July. The rotation is why Ransom-ISAC's YARA rule keys on structure, the eight-character password check, defineClass, ZipInputStream and GZIPOutputStream together, rather than file names.
Stage 3: the implant
ReliaQuest's analysis of the shell (SHA-256 321e1fb0…98bf) is the technical core of this incident. Commands are carried in the X-windchill-req header; PTC's IOC gives the format as ?x8Fmgow with "first character = command selector." Three functions matter:
gs/ theScommand. ReadsieStructProperties.txt, decrypts the LDAP manager password from the application keystore viaWTKeyStoreUtil, then iterates every stored encrypted property: administrative accounts, object-storage credentials, site administrator keys. One request returns all of it in plaintext. ReliaQuest's point is that the LDAP manager credential "typically govern[s] access to Active Directory, email systems, VPN," so a PLM compromise becomes a directory compromise.fl/Flst1. Connects to the Windchill database through the application's ownMethodContextandWTConnection, so queries run under the application's identity, and enumerates vault stream IDs, file names, storage paths and sizes intoflst.txt. The queries reference internal column names such asIDA3A4. This is the map of what to steal.Cldr. A class loader that takes a Base64-encoded ZIP of compiled Java, loads it into memory and executes it. Nothing is written to disk. ReliaQuest reads this as the path to lateral movement or encryption if extortion fails; no such follow-on has been reported.
Responses are GZIP-compressed. Detection therefore needs header logging, response decompression and TLS inspection together; any one alone misses either the commands or the data.
Stage 4: exfiltration and extortion
Cl0p's claimed volumes, 89 GB from Shell and 8 TB from Zebra, are consistent with vault-level theft rather than database dumps. The extortion phase followed the group's Oracle EBS playbook of 2025: on 20 July, emails from compromised third-party accounts went to hundreds of employees per organisation, naming Windchill as the source and giving new contact addresses that were simultaneously posted to the leak site. Listing began three weeks later, first as partial names, then full names from 12 August. GE's reported disappearance from the site would, in Cl0p's pattern, indicate negotiation; that is inference, and GE has not commented.
The scanner's paradox
Censys observed fewer than 100 exposed Windchill instances on 1 June and about 80 on 20 July, a decline of roughly 20% after the advisory. Cl0p named 43 victims. If both figures are right, either the exploitation rate against exposed instances approached half, or a substantial share of victims were reachable in ways passive scanning does not fingerprint: behind Akamai, which fronted about a quarter of observed hosts, on non-standard paths, or through FlexPLM endpoints Censys does not classify as Windchill. ThreatPaper cannot resolve this; PTC could, and has not.
Threat Actor Profile
- Name / Alias: Cl0p (Clop). Tracked as TA505 (ATT&CK G0092), FIN11, Lace Tempest (Microsoft), Graceful Spider (CrowdStrike), Chubby Scorpius, Hive0065. ATT&CK software entry S0611.
- Attribution basis: Ransom-ISAC (with eCrime.ch and DEFUSED), 22 July: extortion emails carry the contact addresses posted on Cl0p's leak site. ReliaQuest, 18 August: "highly likely," on the email match, the header, and the custom-implant pattern. Ransom-ISAC and ReliaQuest hold the same sample from separate incidents. No government attribution for this campaign; the June 2023 Rewards for Justice offer for Cl0p remains open.
- Motivation: Financial. Data theft and extortion without encryption, the group's mode since Accellion (2021).
- Prior mass-exploitation campaigns: Accellion FTA (2021, DEWMODE), SolarWinds Serv-U (2021), GoAnywhere MFT (2023), MOVEit Transfer (2023, LEMURLOOT, 2,770+ organisations), Cleo (2024), Oracle E-Business Suite (2025).
- What changed: ZeroFox characterises this as a shift "from personal data to intellectual property theft." The targets are engineering vaults; the leverage is design data, supplier terms and regulatory submissions rather than PII.
- Sophistication: High in tooling. The implant required source-level knowledge of Windchill's keystore utilities and database schema.
- MITRE ATT&CK techniques (verified on attack.mitre.org, 11 September 2026):
- T1190 Exploit Public-Facing Application
- T1505.003 Server Software Component: Web Shell
- T1555 Credentials from Password Stores; T1552.001 Unsecured Credentials: Credentials In Files (keystore,
ieStructProperties.txt) - T1213 Data from Information Repositories (vault enumeration)
- T1620 Reflective Code Loading (
Cldr) - T1071.001 Application Layer Protocol: Web Protocols; T1560 Archive Collected Data (GZIP)
- T1041 Exfiltration Over C2 Channel
- T1657 Financial Theft (extortion)
Technical Indicators
# Sources: PTC CS473270 changelog (18 Jun–26 Aug 2026), Ransom-ISAC (22 Jul, 14 Aug),
# ReliaQuest (18 Aug). Defanged. PTC notes some IPs may be shared or ephemeral hosting.
c2_priority_block:
- 5.180.41[.]35 # PTC, 18 Jun
- 79.141.160[.]78 # Ransom-ISAC, active incident, 14 Aug
c2_and_exploitation_ips:
- 23.95.238[.]5 # PTC, 26 Aug
- 23.206.251[.]247 # Ransom-ISAC
- 38.60.157[.]212
- 64.177.69[.]57
- 64.177.86[.]200
- 65.20.79[.]73
- 66.163.122[.]78
- 74.50.76[.]146
- 78.128.113[.]10
- 79.141.163[.]103
- 81.27.103[.]18
- 81.27.103[.]68
- 85.9.211[.]83
- 87.58.193[.]42
- 104.194.9[.]14
- 104.238.145[.]147
- 104.243.35[.]0/24
- 104.243.35[.]63
- 104.243.35[.]131
- 111.194.46[.]135
- 137.184.184[.]209
- 138.68.51[.]132
- 144.172.101[.]13
- 162.243.242[.]176
- 172.111.38[.]31
- 185.227.83[.]236
- 204.194.51[.]30
- 206.189.199[.]39
- 209.222.98[.]44
- 212.147.249[.]110
- 216.152.148[.]54
- 216.152.151[.]204
file_hashes:
sha256:
- 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c # JSP shell, PTC 18 Jun
- 321e1fb01eb3462b48ff6ccdef132acc1182e3f7456548439f0d4ead12fd98bf # custom implant, ReliaQuest / Ransom-ISAC
sha1:
- 05af84bfa569366700d826313cdfde44b5efca48
- 8be6f433b443545932821058952916d3c066a8e0
md5: 44 hashes published by PTC on 27 Jul; see Ransom-ISAC advisory §7
web_shell_paths:
known:
- /Windchill/login/7c0a0a34c9d8d53b.jsp
- /Windchill/login/46b158b8607a4c00.jsp
- /Windchill/login/64652883d9de3299.jsp
- /Windchill/login/56c9be44a436c4a2.jsp
- /Windchill/login/4b57d0652345d383.jsp
- /Windchill/login/ec6ba805a076e709.jsp
patterns:
- ^/Windchill/login/[0-9a-f]{16}\.jsp$
- ^/Windchill/login/[0-9a-fA-F]{6}\.jsp(\?cmd=.*)?$
- ^/Windchill/login/dpr_[0-9a-fA-F]{8}\.jsp$
filesystem: <WT_HOME>/codebase/login/*.jsp
http:
command_header: "X-windchill-req: ?x8Fmgow" # first char = command selector; no legitimate use
recon: GET /Windchill/rfa/jsp/login/*.jsp?wsdl with response_bytes == 4045
behaviour: POST to /Windchill/login/*.jsp; multi-MB GZIP responses from .jsp
host_artifacts:
- flst.txt in /tmp or the Windchill working directory
- implant references MethodContext, WTConnection, WTKeyStoreUtil, IDA3A4
extortion_email_subject: "Windchill PDMLink module serious data leak"Legal and Regulatory Response
United States. CISA added CVE-2026-12569 to KEV on 25 June with a 28 June due date under BOD 26-04, flagged "knownRansomwareCampaignUse: Known." No CISA advisory beyond the KEV entry has been issued. No named victim has filed an SEC Form 8-K referencing the incident that ThreatPaper could locate; Zebra, Toast and Fiserv are SEC registrants and have characterised impact as limited or absent, which is consistent with a no-materiality determination. The Rewards for Justice offer of up to $10 million for information tying Cl0p to a foreign government dates from June 2023.
Germany. The response is without precedent in either episode. For CVE-2026-4681 in March, the BKA coordinated state criminal police offices to phone and visit companies overnight; LKA Thuringia said "the companies reached had already been informed by PTC Inc. and had taken security measures." For CVE-2026-12569 the BSI phoned administrators at 2:30 AM on 17 June and emailed the same morning, citing "trustworthy and reliable sources of impending cyberattacks" received through "a partner authority within the National IT Situation Center." The BSI has not identified the partner. The BKA referred questions to the BSI. That a national agency had actionable warning of impending attacks hours before the vendor's public advisory is the clearest evidence in the record that this was a zero-day.
European Union. ENISA's EU Vulnerability Database lists the flaw as EUVD-2026-37831.
Vendor. PTC's Trust Center changelog runs from 17 June to 26 August with twenty entries. PTC has published IOCs, patches, workarounds and detection rules, and states that hosted customers are remediated on their behalf. It has not published how the vulnerability was discovered, whether it was reported or found in exploitation, when the first compromise occurred, or a count of affected customers, and declined CyberScoop's request on all three. The eSupport article CS473270 and the workaround article CS473493 are behind a customer login.
Victims. No regulator has announced an investigation. Philips' statement to Reuters is the only victim confirmation of an intrusion; the rest are investigations or limited-impact statements.
Impact Assessment
- Organisations named on leak site — Confirmed as listings. 43 between 12 and 19 August (BleepingComputer, Ransom-ISAC); "over 40" (SecurityWeek); "50+" (CPO Magazine).
- Confirmed intrusions — Confirmed, partial. Philips (one server, contained); Zebra and Toast (limited impact). Shell, GE investigating.
- Data stolen — Reported. Cl0p claims backups, project plans, facility photographs, drawings, diagrams, blueprints, CAD files and databases; 89 GB (Shell), ~8 TB (Zebra). No samples published; no victim has confirmed a volume.
- Credential exposure — Estimated, high. The implant's
Scommand returns the LDAP manager password and all keystore secrets. ReliaQuest advises assuming the full set is exfiltrated on any compromised server. - Sectors — Confirmed. Manufacturing, automotive, aerospace, retail/apparel (Ransom-ISAC); energy, medtech, fintech, point-of-sale among named victims.
- Exposed attack surface — Reported. Fewer than 100 internet-exposed instances (Censys, 1 June), against PTC's stated 30,000 customers and 1,500 FlexPLM brand and retail customers.
- Ransom demands — Unknown. No figures reported. GE's reported delisting is the only hint of negotiation.
- Follow-on attacks — Not observed. ReliaQuest assesses the class loader enables them; none reported as of 11 September.
- Exploitation start — Unknown. Early June (assessed); not stated by PTC.
Lessons and Defensive Recommendations
For Windchill and FlexPLM administrators
- Patch to the 14 July consolidated builds or later, then patch again for CVE-2026-77645 and -77646 (20 August). Three deserialization flaws in five months means the next one is likely; treat the login servlet as untrusted-input surface and keep the serialization filter workaround in place even when patched.
- Hunt back to early June, not to the advisory date. Search for POSTs to
/Windchill/login/*.jsp, theX-windchill-reqheader,flst.txt, and JSP files incodebase/login/. Run Ransom-ISAC's structural YARA rule; file names rotate, structure does not. - If a shell is found, the keystore is gone. Rotate the LDAP manager password and every secret in
ieStructProperties.txt, then rotate wherever those credentials were reused, and revoke sessions, because rotated passwords do not invalidate existing tokens.
For SOC and detection engineering
- This implant is invisible to URL- and body-based inspection. Log non-standard request headers, decompress responses before inspection, and inspect TLS at the application tier. All three, or coverage is partial.
- Alert on the recon signature:
GET …/login/*.jsp?wsdlreturning 4,045 bytes. It precedes deployment. - Database telemetry will attribute vault enumeration to the application's own service identity. Alert on vault-table queries and multi-MB responses from JSP paths instead of on new accounts.
For manufacturers and their boards
- PLM is the crown-jewel store, and it has been treated as an internal engineering tool. It is now a Cl0p target class alongside file-transfer appliances and ERP. Take it off the internet where the business allows; put it behind a WAF with the PTC rules where it does not.
- Extortion emails will reach hundreds of your employees before any leak-site listing. Brief them.
For PTC and the research community
- Two national police forces have twice woken administrators in the night over this product. The vendor has not said how the flaws were found or how many customers were hit. Disclosure of discovery source and exploitation timeline is the norm after MOVEit; its absence here leaves customers unable to date their own hunting windows.
Sources
- PTC. "Customer & Partner Updates: Remote Code Execution Vulnerability in PTC's Windchill and FlexPLM Solutions". Trust Center, changelog 17 June – 26 August 2026.
- NIST NVD. CVE-2026-12569; CVE-2026-4681; CVE-2026-77645; CVE-2026-77646.
- CISA. Known Exploited Vulnerabilities Catalog, entry for CVE-2026-12569, added 25 June 2026.
- ReliaQuest Threat Research (John Dilgen, Connor Short). "Clop Returns with Custom Implant in Mass-Extortion Campaign". 18 August 2026.
- Ransom-ISAC (Brandon Parsons; Corsin Camichel, Simo Kohonen). "Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)". 22 July 2026, updated 19 August 2026.
- Emily Austin, Censys. "A Chill in the Air: Cl0p Targets Windchill, Another Enterprise Software Product". 30 July 2026.
- Christopher Kunz, heise online. "PTC Windchill: BSI calls admins at night due to critical security vulnerability". 19 June 2026.
- heise online. "WTF: Police responded on Saturday night due to a zero-day". 23 March 2026.
- BleepingComputer. "PTC warns of imminent threat from critical Windchill, FlexPLM RCE bug". 24 March 2026.
- Sergiu Gatlan, BleepingComputer. "Philips and GE investigating Clop ransomware data theft claims". 17 August 2026.
- SecurityWeek. "Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign". 19 August 2026.
- CyberScoop. "The long tail of Clop's PTC hack is just beginning to emerge". 19 August 2026.
- Help Net Security. "JSP webshells being dropped on unpatched PTC Windchill instances". 29 June 2026.
- ZeroFox. "Flash Report: Cl0p Shifts from Personal Data to Intellectual Property Theft". August 2026.
- MITRE ATT&CK. TA505, G0092; Clop, S0611; T1505.003; T1620. Accessed 11 September 2026.
Related Research
ShinyHunters says it vished McKesson employees, took over Okta sessions, and pulled a terabyte from Salesforce and Snowflake between 20 and 25 August 2026. McKesson has confirmed exfiltration of patient data and nothing about how.
Three men who worked in incident response ran BlackCat attacks. One of them was simultaneously negotiating on behalf of ransomware victims — and passing the attackers his own clients' insurance limits.
Between mid-2025 and August 2026, a cybercriminal collective operating primarily under the ShinyHunters brand—alongside associated activity clusters tracked as UNC6040, UNC6240, UNC6395, UNC6661, and...