
PTC Windchill & FlexPLM Zero-Day Data Theft Campaign
Indicators of Compromise
No domains found for this campaign
Campaign Guidance
Remediation, mitigation, notes, history and related intelligence
Remediation/Detections
Apply PTC's security patches immediately, released in stages from 17.06.2026 through 14.07.2026 for all affected Windchill and FlexPLM releases (versions before 11.0 M030 through 13.1.3, plus all Creo Parametric Server/CPS versions).
Block known C2 IP 5.180.41.35 and the rotating attacker IP set at the network perimeter.
Search HTTP access logs for POST requests to /Windchill/login/*.jsp; legitimate Windchill traffic does not POST to this path.
Scan the filesystem under .../Windchill/codebase/login/ for JSP files matching the 16-hex-character or 6-hex-character naming pattern, and hash-check suspicious files against 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c.
Check for flst.txt in /tmp or the Windchill working directory; its presence confirms attacker file-listing activity.
Add a WAF/IDS rule blocking any request containing the header X-windchill-req, and alert on large (multi-MB) POST responses originating from JSP files in the Windchill application tier.
Restrict internet exposure of the Windchill login endpoint where operationally possible, and place remaining instances behind a VPN or trusted access gateway.
If compromise is suspected: isolate the affected servers, collect forensic artifacts, and rotate any exposed credentials before restoring service.
Detection strategies validated against the MITRE ATT&CK Enterprise v19.1 STIX bundle (detects relationships):