Campaigns
PTC Windchill & FlexPLM Zero-Day Data Theft Campaign

PTC Windchill & FlexPLM Zero-Day Data Theft Campaign

ClopWindchillFlexPLMData Theft
A data theft extortion campaign is exploiting CVE-2026-12569, a critical unauthenticated remote code execution vulnerability caused by insecure deserialization (CWE-502) in PTC Windchill PDMLink and FlexPLM product lifecycle management platforms, to deploy persistent JSP webshells and exfiltrate sensitive engineering and product data. ReliaQuest reports the observed tradecraft shares characteristics with previous Clop (Cl0p) campaigns against enterprise file-transfer and data-repository platforms, though the actor behind these specific attacks remains unconfirmed, and victim organizations have begun receiving extortion emails from a new Clop-associated address, [email protected].

Indicators of Compromise

No domains found for this campaign

Campaign Guidance

Remediation, mitigation, notes, history and related intelligence

Remediation/Detections

  • Apply PTC's security patches immediately, released in stages from 17.06.2026 through 14.07.2026 for all affected Windchill and FlexPLM releases (versions before 11.0 M030 through 13.1.3, plus all Creo Parametric Server/CPS versions).

  • Block known C2 IP 5.180.41.35 and the rotating attacker IP set at the network perimeter.

  • Search HTTP access logs for POST requests to /Windchill/login/*.jsp; legitimate Windchill traffic does not POST to this path.

  • Scan the filesystem under .../Windchill/codebase/login/ for JSP files matching the 16-hex-character or 6-hex-character naming pattern, and hash-check suspicious files against 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c.

  • Check for flst.txt in /tmp or the Windchill working directory; its presence confirms attacker file-listing activity.

  • Add a WAF/IDS rule blocking any request containing the header X-windchill-req, and alert on large (multi-MB) POST responses originating from JSP files in the Windchill application tier.

  • Restrict internet exposure of the Windchill login endpoint where operationally possible, and place remaining instances behind a VPN or trusted access gateway.

  • If compromise is suspected: isolate the affected servers, collect forensic artifacts, and rotate any exposed credentials before restoring service.

Detection strategies validated against the MITRE ATT&CK Enterprise v19.1 STIX bundle (detects relationships):

Technique

Detection Strategy

Analytics

T1190

DET0080

AN0219–AN0225

T1505.003

DET0394

AN1108, AN1109, AN1110

T1083

DET0370

AN1040–AN1044

T1071.001

DET0027

AN0075–AN0079

T1041

DET0348

AN0988–AN0991

T1036

DET0127

AN0355–AN0359

T1657

DET0495

AN1361–AN1365

Observed Countries250

AD (151)
AE (208)
AF (987)
AG (929)
AI (464)
AL (409)
AM (871)
AO (252)
AQ (559)
AR (79)
AS (53)
AT (814)
AU (119)
AW (148)
AX (531)
AZ (847)
BA (271)
BB (460)
BD (483)
BE (314)
BF (779)
BG (767)
BH (352)
BI (551)
BJ (351)
BL (64)
BM (262)
BN (171)
BO (349)
BQ (285)
BR (110)
BS (379)
BT (672)
BV (930)
BW (849)
BY (29)
BZ (441)
CA (166)
CC (428)
CD (722)
CF (374)
CG (863)
CH (84)
CI (282)
CK (787)
CL (106)
CM (257)
CN (400)
CO (398)
CR (352)
CU (421)
CV (639)
CW (781)
CX (660)
CY (699)
CZ (372)
DE (696)
DJ (860)
DK (959)
DM (460)
DO (872)
DZ (701)
EC (862)
EE (708)
EG (944)
EH (524)
ER (83)
ES (454)
ET (846)
FI (435)
FJ (442)
FK (939)
FM (847)
FO (993)
FR (814)
GA (300)
GB (969)
GD (27)
GE (768)
GF (252)
GG (249)
GH (440)
GI (665)
GL (91)
GM (313)
GN (798)
GP (13)
GQ (147)
GR (952)
GS (756)
GT (362)
GU (149)
GW (419)
GY (212)
HK (7)
HM (431)
HN (260)
HR (187)
HT (380)
HU (22)
ID (686)
IE (44)
IL (837)
IM (249)
IN (362)
IO (634)
IQ (346)
IR (678)
IS (182)
IT (477)
JE (217)
JM (865)
JO (540)
JP (665)
KE (810)
KG (639)
KH (288)
KI (962)
KM (709)
KN (381)
KP (844)
KR (603)
KW (402)
KY (290)
KZ (558)
LA (666)
LB (23)
LC (229)
LI (349)
LK (895)
LR (869)
LS (228)
LT (414)
LU (474)
LV (861)
LY (445)
MA (855)
MC (246)
MD (367)
ME (367)
MF (299)
MG (272)
MH (688)
MK (774)
ML (292)
MM (404)
MN (150)
MO (301)
MP (958)
MQ (505)
MR (522)
MS (80)
MT (238)
MU (717)
MV (326)
MW (533)
MX (28)
MY (880)
MZ (368)
NA (167)
NC (378)
NE (565)
NF (824)
NG (288)
NI (808)
NL (718)
NO (769)
NP (559)
NR (512)
NU (980)
NZ (698)
OM (172)
PA (581)
PE (971)
PF (310)
PG (83)
PH (878)
PK (425)
PL (219)
PM (279)
PN (593)
PR (477)
PS (815)
PT (596)
PW (636)
PY (50)
QA (463)
RE (297)
RO (341)
RS (580)
RU (472)
RW (217)
SA (340)
SB (476)
SC (617)
SD (650)
SE (974)
SG (304)
SH (175)
SI (616)
SJ (861)
SK (256)
SL (67)
SM (702)
SN (185)
SO (223)
SR (560)
SS (242)
ST (46)
SV (549)
SX (162)
SY (376)
SZ (45)
TC (222)
TD (949)
TF (394)
TG (748)
TH (85)
TJ (633)
TK (668)
TL (593)
TM (429)
TN (728)
TO (432)
TR (616)
TT (213)
TV (244)
TW (526)
TZ (553)
UA (491)
UG (799)
UM (77)
US (267)
UY (443)
UZ (840)
VA (392)
VC (638)
VE (628)
VG (8)
VI (586)
VN (892)
VU (794)
WF (906)
WS (629)
XK (560)
YE (55)
YT (518)
ZA (267)
ZM (99)
ZW (857)