CVE Tools
Back to feed
Exploited in the wild Windchill Cl0p malware FlexPLM PTC

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

ReliaQuest researchers have identified a bespoke JavaServer Pages (JSP) web shell associated with the Clop ransomware operation, targeting PTC Windchill and FlexPLM servers. This implant exploits CVE-2026-12569, a critical vulnerability allowing remote code execution, to establish persistent access within the application.

Unlike generic shells, this tool is specifically engineered to interact with PLM software, enabling attackers to decrypt administrative and LDAP credentials directly from the Windchill keystore. By leveraging the application's own database identities, the malware facilitates the rapid exfiltration of sensitive engineering data and product designs while evading standard signature-based detection.