Clop Gang Used Custom Windchill Web Shell for Data Theft

TL;DR. The Clop ransomware gang deployed a custom Java web shell targeting PTC Windchill and FlexPLM servers to steal data. - The sophisticated shell, designed with specific knowledge of Windchill APIs, decrypted credentials and enumerated file repositories. - ReliaQuest attributed the attacks to Clop based on various forensic indicators and previous exploitation patterns. - This incident highlights a continued focus by threat actors on supply chain and enterprise software vulnerabilities.

Sources

Back to QLANKR News