Clop created custom web shell for Windchill data theft attacks

Clop created custom web shell for Windchill data theft attacks
ReliaQuest uncovered a custom JSP web shell likely tied to Clop that was built specifically for PTC Windchill and FlexPLM, with functions to decrypt credentials, enumerate vaults, and steal files. The activity appears linked to CVE-2026-12569 exploitation and Clop’s broader data theft campaign against enterprise platforms. #Clop #PTCWindchill #FlexPLM #CVE2026-12569

Keypoints

  • The web shell was built specifically for Windchill, not repurposed as a generic tool.
  • It uses Windchill internal classes to access databases and decrypt stored credentials.
  • The implant communicates through the X-windchill-req HTTP header.
  • Its functions include file theft, directory enumeration, file deletion, and code execution.
  • ReliaQuest advises patching Windchill and rotating compromised credentials immediately.

Read More: https://www.bleepingcomputer.com/news/security/clop-created-custom-web-shell-for-windchill-data-theft-attacks/