Clop Gang Used Custom Windchill Web Shell for Data Theft
TL;DR. The Clop ransomware gang deployed a custom Java web shell targeting PTC Windchill and FlexPLM servers to steal data. - The sophisticated shell, designed with specific knowledge of Windchill APIs, decrypted credentials and enumerated file repositories. - ReliaQuest attributed the attacks to Clop based on various forensic indicators and previous exploitation patterns. - This incident highlights a continued focus by threat actors on supply chain and enterprise software vulnerabilities.
- Clop ransomware gang developed a specialized Java web shell for PTC Windchill and FlexPLM servers.
- The web shell exploited CVE-2026-12569 to decrypt credentials and steal files.
- ReliaQuest identified the custom shell, noting its deep knowledge of Windchill's internal architecture.
- This marks an evolution in Clop's mass-exploitation tactics, previously seen with MOVEit and Accellion.
Sources
- Clop created custom web shell for Windchill data theft attacks — bleepingcomputer.com