Exploited in the wild Windchill Cl0p malware FlexPLM PTC
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
CVE Tools coverage
ReliaQuest researchers have identified a bespoke JavaServer Pages (JSP) web shell associated with the Clop ransomware operation, targeting PTC Windchill and FlexPLM servers. This implant exploits CVE-2026-12569, a critical vulnerability allowing remote code execution, to establish persistent access within the application.
Unlike generic shells, this tool is specifically engineered to interact with PLM software, enabling attackers to decrypt administrative and LDAP credentials directly from the Windchill keystore. By leveraging the application's own database identities, the malware facilitates the rapid exfiltration of sensitive engineering data and product designs while evading standard signature-based detection.