Cl0p ransomware affiliates have launched a targeted campaign exploiting vulnerabilities in PTC Windchill and FlexPLM servers to steal confidential engineering and product design information. The threat actors, also tracked as Graceful Spider, Chubby Scorpius, FIN11, and Lace Tempest, are using a combination of software flaws to gain unauthorized access and extract sensitive data from manufacturers, automotive companies, aerospace organizations, and retail apparel firms.
Researchers from Ransom-ISAC, collaborating with eCrime.ch and DEFUSED, identified active exploitation targeting internet-facing deployments. The attackers employ a double-extortion model, pressuring victims with stolen intellectual property even when backup systems allow recovery. Intrusions reportedly began in early June and were followed by mass extortion emails sent through compromised accounts.
How Are Attackers Gaining Access?
The attack chain begins with a pre-authentication information disclosure vulnerability in the FlexPLM WSDL endpoint, combined with exploitation of a weakness in the Windchill login servlet. By chaining these two flaws together, attackers achieve remote code execution without needing valid credentials, establishing a foothold on target servers.
The critical vulnerability at the center of this campaign is CVE-2026-12569, a deserialization flaw affecting PTC Windchill PDMLink and FlexPLM versions prior to 11.0 M030. With a CVSS score of 9.8, the vulnerability was disclosed on June 17 and added to CISA’s Known Exploited Vulnerabilities catalog on June 25. After gaining initial access, operators deploy JSP webshells, examine server files, and prepare engineering data for exfiltration.
What Does the Extortion Campaign Look Like?
Beginning July 20, Ransom-ISAC observed emails with the subject line “Windchill PDMLink module serious data leak” distributed to hundreds of employees at affected organizations. This internal distribution tactic increases pressure on executives and incident response teams before any public disclosure occurs. The approach mirrors tactics used in previous Oracle EBS campaigns, though current operations utilize new email addresses.
Organizations receiving these extortion messages should preserve all email evidence and headers, conduct internal validation investigations, and educate employees about reporting suspicious communications. Security teams need to hunt for indicators of compromise dating back to early June, apply vendor patches immediately, and follow published remediation guidance.
What Actions Should Organizations Take?
Security teams should prioritize externally accessible Windchill and FlexPLM servers for immediate patching. Organizations should search for unexpected JSP files, monitor unusual outbound network activity, and review access logs for reconnaissance requests. Several indicators of compromise have been published, including IP addresses 216.152.148.54, 216.152.151.204, 104.243.35.63, and 5.180.41.35. Teams should also watch for the malicious HTTP header “X-windchill-req: ?x8Fmgow” and hunt for webshell paths matching the pattern Windchill/login/[0-9a-f]{16}.jsp.
The reconnaissance request “GET /Windchill/rfa/jsp/login.jsp?wsdl” with a response size of 40454 bytes represents an observed pre-attack indicator. Organizations should also monitor for file artifacts named flst.txt and the published SHA-256 hash 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c.
Source: Cybersecurity News