
1. Introduction
The Unified Threat Advisory is a coordinated Cyber Intelligence effort led by Ransom-ISAC, with collaboration from eCrime.ch and DEFUSED. This update covers active Cl0p ransomware affiliate exploitation targeting internet-exposed PTC Windchill and FlexPLM deployments.
2. Overview
Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling unauthenticated remote code execution and deployment of hex-named JSP webshells under /Windchill/login/. Post-exploitation includes filesystem enumeration via flst.txt, staging of engineering/design data, and double-extortion data theft. Confirmed victim sectors include Manufacturing, Automotive, Aerospace, and Retail/Apparel.
This advisory issues four new C2 indicators alongside previously distributed IOCs from 7/8/2026, 7/1/2026, 6/25/2026, and 6/18/2026.
- Windchill RCE Chain — CVSS 9.8
- FlexPLM WSDL Disclosure — CVSS 7.5
PTC has released fixed builds for both defects; unpatched, internet-exposed Windchill/FlexPLM instances remain the primary attack surface.
3. Key Highlights
- Threat actor: Cl0p ransomware affiliate activity
- Initial access: FlexPLM WSDL disclosure + Windchill login servlet flaw
- Post-exploitation: JSP webshells,
flst.txtfile listing, data staging - Malicious header:
X-windchill-req: ?x8Fmgow - Hunt path:
/Windchill/login/[0-9a-f]{16}.jsp - Hash IOC (SHA-256):
55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c - Pre-attack recon:
GET /Windchill/rfa/jsp/login/*.jsp?wsdlwithresponse_bytes = 4045
4. Extortion campaign
On 20 July, Ransom-ISAC began observing an alleged Cl0p ransomware (aka Graceful Spider, Chubby Scorpius, FIN11, Lace Tempest) data extortion campaign sending emails with a subject line, “Windchill PDMLink module serious data leak” to an unknown number of affected organizations (Figure 1 & Figure 2). The extortion emails appear to originate from randomly compromised accounts, are sent to hundreds of users within an impacted organization and include Cl0p’s latest contact information (Figure 3). This extortion approach is consistent with what we observed with the Oracle EBS campaign last year, except for the use of new email addresses.

Figure 1: Extortion email sent to employees across the victim organization, claiming Cl0p has breached the company and attributing the compromise to its PTC Windchill software.

Figure 2: A further extortion email to the same recipients, reinforcing the breach claim and the attribution to PTC Windchill to intensify pressure — publicly confirming the link to the Windchill campaign.

Figure 3: Update posted to Cl0p’s dedicated data leak site listing the new email addresses victims are directed to use for contact.
5. The vulnerability
We suspect that threat actors affiliated with Cl0p ransomware most likely exploited CVE-2026-12569 as a zero-day vulnerability in early June 2026. CVE-2026-12569 (CVSS v3.1 9.8 / 10; vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) was disclosed on 17 June, 2026 and is described as a critical-severity remote code execution (RCE) vulnerability in PTC Windchill PDMlink and PTC FlexPLM that may be exploited through the deserialization of untrusted data. CVE-2026-12569 also impacts Windchill and FlexPLM releases prior to 11.0 M030. CISA added CVE-2026-12569 to their known exploited vulnerabilities (KEV) catalog on 25 June, 2026. In the observed intrusions, this RCE is chained with a separate pre-authentication information-disclosure defect in the FlexPLM WSDL endpoint (CVSS v3.1 7.5) to enable unauthenticated exploitation.
6. New Indicators of Compromise (2026-07-22)
216.152.148.54216.152.151.204104.243.35.635.180.41.35(priority block)
7. Recommended actions
Organizations receiving emails matching this pattern should conduct threat hunting dating back to early June 2026, using the indicators of compromise (IOCs) in PTC’s advisory as soon as possible and follow PTC’s remediation steps outlined in PTC’s Support Article. This situation is still developing.
8. Outlook
We will continue to monitor for any updates with this latest campaign. As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign.
Subscribe to Ransom-ISAC and eCrime.ch feeds for updated IOCs, signatures, and hunting content — www.ransom-isac.org.

