Cl0p ransomware affiliates have opened a new front in their extortion campaigns, actively exploiting internet-exposed PTC Windchill and FlexPLM deployments to steal engineering and product-design data from manufacturers, automakers, and aerospace firms worldwide.
The activity, tracked in a coordinated Unified Threat Advisory from Ransom-ISAC, eCrime.ch, and DEFUSED, marks the latest evolution in Cl0p’s shift toward mass-exploitation, no-encryption data-theft operations.
The intrusion chain begins with a pre-authentication information-disclosure flaw in the FlexPLM WSDL endpoint, which leaks internal system details attackers use to prepare a follow-on exploit against a server-side defect in the Windchill login servlet.
Cl0p Exploits PTC Windchill & FlexPLM Flaw
Chaining these two issues grants unauthenticated remote code execution, after which operators drop hex-named JSP webshells under the /Windchill/login/ directory path.
Investigators identified a distinctive hunting signature for this reconnaissance phase: GET requests to /Windchill/rfa/jsp/login/*.jsp?wsdl returning a response size of 4045 bytes, alongside a malicious request header, X-windchill-req: ?x8Fmgow, tied to the exploitation stage.

Once inside, the affiliates enumerate the filesystem using a file named flst.txt before staging sensitive engineering and design data for exfiltration, consistent with Cl0p’s long-running double-extortion model.
Confirmed victims span Manufacturing, Automotive, Aerospace, and Retail/Apparel sectors, underscoring the operational sensitivity of PLM systems in these industries.
The core defect, CVE-2026-12569, is a critical deserialization-of-untrusted-data flaw in Windchill PDMLink and FlexPLM, carrying a CVSS score of 9.8, and is believed to have been exploited as a zero-day beginning in early June 2026, weeks before its public disclosure on June 17.
CISA added the flaw to its Known Exploited Vulnerabilities catalog just eight days later, on June 25, as webshell attacks continued to escalate. A separate, lower-severity FlexPLM WSDL disclosure bug, rated 7.5, provides the reconnaissance foothold attackers pair with the RCE for fully unauthenticated compromise.
PTC has since shipped fixed builds, though organizations running Windchill or FlexPLM releases prior to 11.0 M030 that remain internet-facing continue to represent the primary attack surface.

Beginning July 20, researchers observed Cl0p, also tracked as Graceful Spider, Chubby Scorpius, FIN11, and Lace Tempest, sending mass extortion emails titled “Windchill PDMLink module serious data leak” to hundreds of employees across victim organizations, a pressure tactic nearly identical to its Oracle E-Business Suite campaign from the prior year, save for the use of newly registered contact addresses.
As of July 22, Cl0p has not yet listed any Windchill-related victims on its dark web leak site, suggesting negotiations may still be underway behind the scenes.
Security teams should treat this as an active, developing threat given the confirmed pre-disclosure exploitation window.
- Threat-hunt retroactively to early June 2026 using published IOCs, including hash 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c and the webshell path pattern /Windchill/login/[0-9a-f]{16}.jsp.
- Block or monitor newly issued C2 infrastructure, including 5.180.41.35, flagged as a priority block, alongside 216.152.148.54, 216.152.151.204, and 104.243.35.63.
- Apply PTC’s remediation guidance immediately and remove Windchill/FlexPLM instances from direct internet exposure where possible.
- Audit for anomalous flst.txt file listings and outbound data transfers tied to PLM directories.
Given Cl0p’s track record of exploiting file-transfer and enterprise software zero-days from MOVEit to Oracle EBS, this campaign reinforces that internet-facing PLM and supply-chain platforms remain a preferred entry point for large-scale extortion operations.