Clop Is Back: This Time It’s Targeting Windchill and FlexPLM

If the past several years have taught us anything, it’s that Clop doesn’t wait for organizations to patch.

Originally emerging around 2019 as a ransomware operation, Clop has evolved into one of the most prolific data extortion groups in the world. Rather than relying solely on traditional ransomware deployments, the group increasingly focuses on exploiting newly disclosed zero-day and n-day vulnerabilities in widely deployed enterprise software to steal sensitive data at scale. We’ve seen this playbook before with Accellion FTA, GoAnywhere MFT, MOVEit Transfer, Cleo, Oracle E-Business Suite – and now, PTC Windchill and FlexPLM.

Multiple recent reports indicate that Clop is actively exploiting CVE-2026-12569, a critical remote code execution vulnerability affecting Internet-facing PTC Windchill and FlexPLM systems. Successful exploitation allows unauthenticated attackers to execute code, deploy web shells, and exfiltrate valuable intellectual property and engineering data before moving directly to extortion. As with previous Clop campaigns, organizations may never see ransomware encryption – the theft of sensitive data alone is often sufficient to pressure victims into negotiations.

Immediate Actions

If your organization operates Windchill or FlexPLM:

  • Immediately identify all Internet-exposed Windchill and FlexPLM instances.
  • Apply PTC’s security updates for all affected versions without delay.
  • Review PTC’s published Indicators of Compromise (IOCs) and hunt for evidence of web shell deployment or unauthorized activity.
  • Inspect authentication logs, web server logs, and application logs for suspicious requests associated with exploitation attempts.
  • Look for signs of data staging or unusual outbound network traffic, particularly involving engineering repositories and PLM data.
  • Reset credentials and review privileged accounts if compromise is suspected.
  • Engage your incident response team immediately if any indicators are identified – early containment can significantly reduce downstream impact.

Clop has repeatedly demonstrated that it can weaponize newly disclosed vulnerabilities within days (sometimes hours) of public disclosure. Organizations running exposed enterprise applications should assume that patch windows are measured in hours, not weeks.

The lesson remains the same: when Clop shifts its attention to a new platform, every unpatched Internet-facing system becomes a potential target.

If your organization suspects compromise or simply wants an expert set of eyes on your exposure before Clop comes knocking, CYPFER’s incident response team is available 24/7 to help with rapid containment, investigation, and recovery. Learn more about how you can protect your organization with CYPFER.

Reference: https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability?srsltid=AfmBOoqLetBG5IO-nQQZkxyovAkfwY9tg1SJdsD3W9N-8LLan4uihgMX

Ähnliche Themen

View All Insights Btn-arrowIcon for btn-arrow

Your Complete Cyber Security Partner:
Cyber-Bedrohungen aller Art

At CYPFER, we don’t just protect your business—we become part of it.

Als Erweiterung Ihres Teams konzentrieren wir uns ausschließlich auf die Cybersecurity, damit Sie sich um Ihr Kerngeschäft kümmern können. Von Incident Response und Ransomware Recovery bis zu digitaler Forensik und Cyber-Risikobewertung – wir integrieren unsere Arbeit nahtlos in Ihre Abläufe. Wir sind rund um die Uhr für Sie da, um Bedrohungen direkt zu bekämpfen und zukünftige Gefahren zu verhindern.

Wenn Sie sich für CYPFER entscheiden, entscheiden Sie sich für beispiellose Expertise und einzigartiges Engagement. Gemeinsam können wir die Cyber-Resilienz in Ihrem Unternehmen verbessern und es so schützen.

Team of professionals working collaboratively at a desk, focusing on laptops and business tasks in a modern office setting

Holen Sie sich jetzt Cyber Certainty™

Was auch immer Ihre Umstände sind: Wir möchten Ihrem Unternehmen dabei helfen, erfolgreich zu sein und zu bleiben – ganz ohne Sorgen um Cyberattacken.

CYPFER kontaktieren Btn-arrowIcon for btn-arrow