Threat Actors Exploit Vulnerabilities in PTC Windchill and FlexPLM in New Ransomware Campaign
In a concerning development for businesses across various sectors, threat actors linked to the notorious Cl0p ransomware group, which also goes by the aliases Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest, have been identified exploiting vulnerabilities in internet-exposed installations of PTC Windchill and FlexPLM. This exploitation is part of a newly initiated data extortion campaign that poses significant risks to organizations, particularly within manufacturing, automotive, aerospace, and retail industries.
Security experts released a coordinated advisory detailing the nature of the attacks. They elucidated that attackers are leveraging a pre-authentication information disclosure vulnerability within the FlexPLM WSDL endpoint, in conjunction with a server-side flaw found in the Windchill login servlet. This malfeasance enables unauthorized remote code execution, allowing the attackers to deploy JSP web shells—malicious scripts that facilitate further infiltration—under the /Windchill/login/ directory.
Once these attackers secure an initial foothold within a targeted organization, they conduct extensive reconnaissance. This includes file system enumeration and staging sensitive engineering and design data. Ultimately, this leads to a strategy of double extortion, where data theft not only comprises sensitive information but also involves threats to publish this data if ransom demands are not met.
The vulnerabilities under scrutiny are believed to be connected to a critical security flaw identified as CVE-2026-12569, which boasts a CVSS score of 9.3, placing it in the category of critical vulnerabilities. Notably, this flaw was incorporated into the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog in the previous month, highlighting the urgency of its remediation.
Further complicating matters, PTC—responsible for the software in question—has issued warnings to its customers. The organization acknowledged the ongoing threat by stating that it has received multiple reports regarding increased malicious activities being observed in the wild. These unknown attackers are actively exploiting the identified vulnerabilities to deploy JSP web shells on susceptible systems, which can lead to catastrophic data breaches.
Researchers Brandon Parsons, Corsin Camichel, and Simo Kohonen provided insight into the intricacies of the attack methods involved. They noted that the exploit of CVE-2026-12569 is often chained with a separate pre-authentication information disclosure defect—specifically in the FlexPLM WSDL endpoint, which has a CVSS score of 7.5. This combination allows for authenticated exploitation, significantly increasing the risks associated with these vulnerabilities.
In an effort to aid organizations in protecting themselves against these threats, Ransom-ISAC, in collaboration with other cybersecurity institutions, has disclosed four specific IP addresses tied to these attacks. These addresses align with those previously identified by PTC:
- 216.152.148.54
- 216.152.151.204
- 104.243.35.63
- 5.180.41.35
Suspicious extortion emails, believed to be sent by these malicious actors, often originate from accounts that have been previously compromised. This tactic allows the attackers to reach hundreds of users within an impacted organization, providing them with specific instructions on how to engage with the Cl0p ransomware affiliates.
Further affirming the scale of this issue, ReliaQuest—another cybersecurity monitoring body—reported that it has observed the continued exploitation of CVE-2026-12569. This exploitation facilitates “unauthenticated remote code execution and JSP web shell deployment,” allowing for remote command execution and the exfiltration of sensitive product data.
While the precise identity of the perpetrators remains uncertain, the observed methodologies bear striking similarities to earlier campaigns executed by the Cl0p group, particularly those aimed at undermining enterprise applications and hijacking valuable data repositories. The Cl0p gang has built a reputation for targeting pervasive security flaws in widely-used enterprise software to facilitate their data theft and extortion operations.
Historically, their campaigns have successfully weaponized vulnerabilities in file transfer appliances, including those supplied by Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer, along with exploiting flaws within the Oracle E-Business Suite.
In summary, this emerging threat underscores the critical need for organizations to remain vigilant and proactive in patching vulnerabilities and enhancing their cybersecurity measures. The combination of sophisticated techniques and critical vulnerabilities poses a significant challenge, demanding attention from IT and security professionals alike. As the landscape of cyber threats continues to evolve, organizations must prioritize safeguarding against potential incursions that could threaten their operational integrity and sensitive data.
