Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product Designs

Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product Designs










Cl0p ransomware affiliates are exploiting exposed PTC Windchill and FlexPLM servers to steal engineering and product-design data.

The campaign combines software flaws to gain access without credentials, install hidden server-side access, and remove sensitive files before demanding payment.

The activity places manufacturers, automotive firms, aerospace organizations, and retail apparel companies at particular risk because Windchill systems can hold highly valuable product records.

Attackers use a double-extortion model, allowing them to pressure victims with stolen data even when systems can be recovered from backups.

Analysts at Ransom-ISAC, working with eCrime.ch and DEFUSED, identified active exploitation and warned that unpatched, internet-facing deployments remain the main entry point.

The activity is linked to Cl0p affiliates, an operation also known as Graceful Spider, Chubby Scorpius, FIN11, and Lace Tempest.

Ransom-ISAC said in a report shared with Cyber Security News (CSN) that the intrusions appear to date back to early June and have been followed by mass extortion emails sent through randomly compromised accounts.

The messages force organizations to investigate possible theft quickly while also protecting employees from follow-on phishing and social-engineering attempts.

Cl0p Hackers Exploit Windchill Servers

The attack begins with a pre-authentication information disclosure in the FlexPLM WSDL endpoint, followed by abuse of a weakness in the Windchill login servlet.

Chaining the two flaws gives attackers a way to execute code remotely without a valid account and establish a foothold on the server.

The key vulnerability, CVE-2026-12569, is a critical deserialization flaw with a CVSS score of 9.8 that affects PTC Windchill PDMLink and FlexPLM releases before 11.0 M030. It was disclosed on June 17, while CISA added it to its Known Exploited Vulnerabilities catalog on June 25.

After gaining access, the operators deploy JSP webshells, inspect server files, and stage engineering data for theft.

Extortion email sent to employees across the victim organization (Source - Ransom-ISAC)
Extortion email sent to employees across the victim organization (Source – Ransom-ISAC)

The incident follows the pattern seen in recent Cl0p ransomware actor campaigns, where an exposed enterprise application can become a direct route to confidential data and public extortion.

This is especially concerning for organizations that use Windchill to manage design documents, product specifications, and development workflows.

A successful breach can expose intellectual property that is difficult to replace and may give competitors or criminal buyers insight into unreleased products.

The attackers did not need to break through an employee mailbox or trick a user into opening a malicious attachment.

Instead, they targeted a public-facing application, underscoring why organizations should continuously identify internet-exposed systems and rapidly apply security updates for high-impact vulnerabilities.

Extortion Campaign Raises Pressure

On July 20, Ransom-ISAC began observing emails with the subject line “Windchill PDMLink module serious data leak” sent to hundreds of employees at affected organizations.

This approach spreads the breach allegation internally and increases pressure on executives and incident-response teams before a victim is named publicly.

The tactic is similar to last year’s Oracle EBS campaign, although the current operation uses new email addresses.

A further extortion email to the same recipients (Source - Ransom-ISAC)
A further extortion email to the same recipients (Source – Ransom-ISAC)

Organizations facing such messages should preserve the emails and headers, validate the claim through internal investigation, and remind employees to report suspicious communications, as seen in reported Oracle EBS breach investigations.

The organizations receiving matching emails should hunt for compromise dating back to early June, use published indicators, apply fixed builds, and follow the vendor’s remediation guidance.

Security teams should give immediate priority to externally reachable Windchill and FlexPLM servers, check for unexpected JSP files and unusual outbound activity, and review access logs for the noted reconnaissance request.

Monitoring CISA KEV catalog alerts can also help teams focus patching work on flaws known to be exploited.

The case also highlights the danger of unauthenticated code-execution flaws in business-critical systems.

Similar unauthenticated remote code risks have shown how quickly a server vulnerability can become a broader data-theft incident when patches are delayed.

Indicators of compromise (IoCs):-

Type Indicator Description
IP address 216.152.148.54 Newly published C2 indicator
IP address 216.152.151.204 Newly published C2 indicator
IP address 104.243.35.63 Newly published C2 indicator
IP address 5.180.41.35 Newly published C2 indicator
SHA-256 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c Published hash indicator
HTTP header X-windchill-req: ?x8Fmgow Malicious request header
Webshell path Windchill/login/[0-9a-f]{16}.jsp Hunt path for hex-named JSP webshells
File name flst.txt File listing artifact
Reconnaissance request GET /Windchill/rfa/jsp/login.jsp?wsdl Observed pre-attack WSDL request
Response size 40454 bytes Response size associated with the reconnaissance request

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

ALERT!: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

The post Cl0p Hackers Exploit Windchill Servers to Steal Companies’ Secret Product Designs appeared first on Cyber Security News.






Tushar Subhra Dutta





Go to cyber-security-news





Posted

in

, ,

by