Clop exploited the zero-day CVE-2026-12569 in PTC’s Windchill and FlexPLM platforms to conduct a large-scale data theft extortion campaign against dozens of organizations. Researchers said the group used a custom Windchill web shell to steal credentials, maintain access, and move quickly across victim systems. #Clop #PTC #Windchill #FlexPLM #CVE-2026-12569
Keypoints
- Clop began sending extortion emails to victims in mid-July.
- The campaign targeted a critical zero-day in PTC Windchill and FlexPLM.
- The flaw allowed unauthenticated remote code execution.
- ReliaQuest found a custom web shell built for Windchill-based access and theft.
- Victims included major companies such as Toast, Zebra, GE, Philips, and Shell.
Read More: https://cyberscoop.com/clop-zero-day-attacks-ptc-windchill-flexplm/