Connect with us

Security

Exploiting Unauthenticated RCE Vulnerabilities in PTC Windchill and FlexPLM through Cl0p Affiliates

Published

on

Cl0p Ransomware Group Exploiting PTC Windmill and FlexPLM Vulnerabilities

A recent data extortion campaign linked to the Cl0p ransomware group is taking advantage of vulnerabilities found in internet-exposed PTC Windmill and FlexPLM deployments. This campaign involves exploiting flaws in the systems to gain unauthorized access and carry out double extortion data theft.

The attackers are utilizing a combination of pre-authentication information disclosure in the FlexPLM WSDL endpoint and a server-side flaw in the Windchill login servlet to achieve unauthenticated remote code execution. This allows them to deploy malicious JSP web shells on the compromised systems.

Industries targeted by this campaign include manufacturing, automotive, aerospace, and retail sectors. The threat actors are believed to be leveraging CVE-2026-12569, a critical security vulnerability in PTC Windmill, to carry out their attacks. This flaw was recently added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog.

PTC has issued a warning to its customers regarding heightened threat activity and the exploitation of the vulnerability to deploy JSP web shells. Researchers have noted that the attackers are chaining the RCE vulnerability with an information disclosure defect in the FlexPLM WSDL endpoint to enable their malicious activities.

Data Breach

Ransom-ISAC has identified several IP addresses associated with the attacks, which align with those shared by PTC. The malicious actors are sending extortion emails from compromised accounts to multiple users within targeted organizations, providing instructions on how to contact the Cl0p ransomware group.

Security firm ReliaQuest has observed threat actors actively exploiting the vulnerabilities to carry out remote code execution and sensitive data exfiltration. While the identity of the attackers remains unknown, their tactics are consistent with previous Cl0p campaigns that focus on targeting enterprise applications and valuable data repositories.

See also  Enhanced Security Alert: Windows PowerShell Now Notifies Users of Invoke-WebRequest Script Risks

The Cl0p ransomware group has a history of exploiting security flaws in popular enterprise products to conduct data theft and extortion attacks. Previous campaigns by the group have targeted various file transfer appliances and vulnerabilities in Oracle E-Business Suite.

Trending