CVE Tools
Back to feed
Exploited in the wild PTC Windchill Clop ransomware FlexPLM PTC

Clop created custom web shell for Windchill data theft attacks

BleepingComputer·By Lawrence Abrams··4 min read
CVE Tools coverage

ReliaQuest identified a custom-built Java web shell attributed to the Clop ransomware gang, specifically engineered for PTC Windchill and FlexPLM servers. This implant leverages the critical remote code execution vulnerability CVE-2026-12569 to decrypt stored credentials and exfiltrate files from application vaults. Because the tool integrates directly with Windchill's internal APIs, database queries run under the application's service identity, potentially evading standard detection methods. Organizations running affected versions are urged to apply patches immediately and investigate any unusual JSP files referencing the 'X-windchill-req' header.