Skip to main content
Back to Blog
Threat Advisory3 min readJuly 22, 2026Updated July 27, 2026
PTCWindChillFlexPLMCl0pRansomwareExploit

Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569)

In collaboration with: eCrime.ch & DEFUSED

eCrime.chDEFUSED

A coordinated Unified Threat Advisory covering active Cl0p ransomware affiliate exploitation of internet-exposed PTC Windchill and FlexPLM deployments — chaining a pre-auth FlexPLM WSDL information disclosure with a Windchill login servlet flaw for unauthenticated RCE, JSP webshell deployment, and double-extortion data theft.

Brandon Parsons

Contributors: Corsin Camichel, Simo Kohonen

Cl0p Exploitation of PTC Windchill & FlexPLM cover image
Update — 27 July 2026: This advisory has been refreshed to incorporate the expanded indicator set published in PTC’s advisory as of its 7/27/2026 update (eSupport article CS473270). See Section 7: Additional Indicators of Compromise for the newly added network, file-hash, and webshell indicators.

1. Introduction

The Unified Threat Advisory is a coordinated Cyber Intelligence effort led by Ransom-ISAC, with collaboration from eCrime.ch and DEFUSED. This update covers active Cl0p ransomware affiliate exploitation targeting internet-exposed PTC Windchill and FlexPLM deployments.

2. Overview

Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling unauthenticated remote code execution and deployment of hex-named JSP webshells under /Windchill/login/. Post-exploitation includes filesystem enumeration via flst.txt, staging of engineering/design data, and double-extortion data theft. Confirmed victim sectors include Manufacturing, Automotive, Aerospace, and Retail/Apparel.

This advisory issues four new C2 indicators alongside previously distributed IOCs from 7/8/2026, 7/1/2026, 6/25/2026, and 6/18/2026.

  • Windchill RCE Chain — CVSS 9.8
  • FlexPLM WSDL Disclosure — CVSS 7.5

PTC has released fixed builds for both defects; unpatched, internet-exposed Windchill/FlexPLM instances remain the primary attack surface.

3. Key Highlights

  • Threat actor: Cl0p ransomware affiliate activity
  • Initial access: FlexPLM WSDL disclosure + Windchill login servlet flaw
  • Post-exploitation: JSP webshells, flst.txt file listing, data staging
  • Malicious header: X-windchill-req: ?x8Fmgow
  • Hunt path: /Windchill/login/[0-9a-f]{16}.jsp
  • Hash IOC (SHA-256): 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c
  • Pre-attack recon: GET /Windchill/rfa/jsp/login/*.jsp?wsdl with response_bytes = 4045

4. Extortion campaign

On 20 July, Ransom-ISAC began observing an alleged Cl0p ransomware (aka Graceful Spider, Chubby Scorpius, FIN11, Lace Tempest) data extortion campaign sending emails with a subject line, “Windchill PDMLink module serious data leak” to an unknown number of affected organizations (Figure 1 & Figure 2). The extortion emails appear to originate from randomly compromised accounts, are sent to hundreds of users within an impacted organization and include Cl0p’s latest contact information (Figure 3). This extortion approach is consistent with what we observed with the Oracle EBS campaign last year, except for the use of new email addresses.

Extortion email sent to employees across the victim organization, claiming Cl0p has breached the company and attributing the compromise to its PTC Windchill software

Figure 1: Extortion email sent to employees across the victim organization, claiming Cl0p has breached the company and attributing the compromise to its PTC Windchill software.

A further extortion email to the same recipients, reinforcing the breach claim and the attribution to PTC Windchill

Figure 2: A further extortion email to the same recipients, reinforcing the breach claim and the attribution to PTC Windchill to intensify pressure — publicly confirming the link to the Windchill campaign.

Update posted to Cl0p's dedicated data leak site listing the new email addresses victims are directed to use for contact

Figure 3: Update posted to Cl0p’s dedicated data leak site listing the new email addresses victims are directed to use for contact.

5. The vulnerability

We suspect that threat actors affiliated with Cl0p ransomware most likely exploited CVE-2026-12569 as a zero-day vulnerability in early June 2026. CVE-2026-12569 (CVSS v3.1 9.8 / 10; vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) was disclosed on 17 June, 2026 and is described as a critical-severity remote code execution (RCE) vulnerability in PTC Windchill PDMlink and PTC FlexPLM that may be exploited through the deserialization of untrusted data. CVE-2026-12569 also impacts Windchill and FlexPLM releases prior to 11.0 M030. CISA added CVE-2026-12569 to their known exploited vulnerabilities (KEV) catalog on 25 June, 2026. In the observed intrusions, this RCE is chained with a separate pre-authentication information-disclosure defect in the FlexPLM WSDL endpoint (CVSS v3.1 7.5) to enable unauthenticated exploitation.

6. New Indicators of Compromise (2026-07-22)

  • 216.152.148.54
  • 216.152.151.204
  • 104.243.35.63
  • 5.180.41.35 (priority block)

7. Additional Indicators of Compromise (PTC advisory — updated 2026-07-27)

The following indicators reflect the expanded set published in PTC’s advisory (CS473270) as of its 7/27/2026 update, and are provided in addition to the indicators listed above. As always, validate network indicators against your own environment before blocking — some may correspond to shared or ephemeral hosting.

Network indicators (IPv4)

  • 23.206.251.247
  • 38.60.157.212
  • 64.177.69.57
  • 64.177.86.200
  • 65.20.79.73
  • 66.163.122.78
  • 74.50.76.146
  • 78.128.113.10
  • 79.141.163.103
  • 81.27.103.18
  • 81.27.103.68
  • 85.9.211.83
  • 87.58.193.42
  • 204.194.51.30
  • 206.189.199.39
  • 209.222.98.44
  • 212.147.249.110

File hashes (MD5)

PTC published the following MD5 hashes associated with the campaign:

051e8962b68f426c87ae84b19b8de4af
0cb44545fc4146b5a0274c88078d31f1
23ac6ac152a34d90b986fec9a15b96df
314cc95c21fb4f168cb3b18707b13b68
3432991218cf4dbc93bff5133e220954
36588fe667a44114936d58aac98f2cdb
3f4db01ab0b645c0801c90e9a0efa353
43aec5fd10de4f1dbe7622b94e76d7a6
47a5d023d0774b5f817643effa562708
50dc0c2a9fbc4caa67f1f6ad9fc75b9b
547ce27d08d34630b69676bd92c73447
6cb2622eb4fb4642b4280672123fae3e
6e93802ac6f24eaf09a4ff1d3c9cfe0c
6f0869b8f23942a091e3e6051eaeaa94
72b0cfb581aa4c26a701a88ccaedff8f
8854097a04c04199a97e35cd7d9123a3
8e362ecf0aa34cb396fe78f43d25c2e9
8ea1cf1b88cb4f76b55670df28807ce2
92cb2682f9be4916a438bc3af4b87054
95b8d59f0e914c6caa5ddc9bf666e788
9eae6eac94de4092a8835741aca89d56
a2552b05cd134806a4bda10d56c8cdfe
a2a9c63fa8324e11af773ce9866d7c52
a82bd8887f76416e9ee860e2bd615910
a85e1d0394ae43a8803916c71c7273a1
ad02c4634b4e4d26950fa8624cd39b73
bb3bfdea4edf4d949b5ffb0616222ed2
c0e7410e9a074e15980aa29f674624d4
c22e1d0a2ced49ccacb3fae025b2eb00
c8a79685ffbe41bdb5692e4ba8771d02
c8d2be891f85455d8e139e0428434203
cd68100dfacf4af2a0e198a35c4d8097
ce03bd3b07ea4ed48a99133432ae25ab
d1a7ac95794e47a7a7d8764215ed2d5d
d29f364287ce4f0d9f11e3e889ee032e
da0b8f9bf1b14ae59fcf251bb7bb2ee3
e16ea289e58942a6b33c34d51dc8b87b
e3e507da427448b09d51b4c860f58919
e7dea7cacb124e239e727ddef128bedd
eb21de20c0434109b930047f0e08448a
ee7773a5c3b62ebf0f9df3a7b8a09c02
f31d7a43e41847b9b1cb07fe3fced2d3
f352c90f4d394cc2aa92b01ecc7ac777
f529d0db850d44b8807dfd365cd46105

File hashes (SHA-1)

  • 05af84bfa569366700d826313cdfde44b5efca48
  • 8be6f433b443545932821058952916d3c066a8e0

Webshell artifacts

  • Hex-named JSP webshells written under /Windchill/login/ matching [0-9a-f]{16}.jsp — observed filenames include 46b158b8607a4c00.jsp, 4b57d0652345d383.jsp, 56c9be44a436c4a2.jsp, 64652883d9de3299.jsp, 7c0a0a34c9d8d53b.jsp, and ec6ba805a076e709.jsp.
  • Webshells following the dpr_<8 hex>.jsp naming convention (e.g. dpr_0123abcd.jsp).

Organizations receiving emails matching this pattern should conduct threat hunting dating back to early June 2026, using the indicators of compromise (IOCs) in PTC’s advisory as soon as possible and follow PTC’s remediation steps outlined in PTC’s Support Article. This situation is still developing.

9. Outlook

We will continue to monitor for any updates with this latest campaign. As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign.

Subscribe to Ransom-ISAC and eCrime.ch feeds for updated IOCs, signatures, and hunting content — www.ransom-isac.org.

References

Found this article helpful?

Share it with your network

Continue Reading

Explore more expert insights and threat intelligence from the Ransom-ISAC community