In brief: A custom web shell associated with Clop exploits a critical vulnerability in PTC Windchill/FlexPLM to decrypt credentials and map sensitive engineering data vaults for extortion purposes.
Following exploitation of a critical vulnerability in PTC Windchill and FlexPLM, attackers deployed a custom JSP web shell that decrypts credentials and maps sensitive engineering data. Security researchers at ReliaQuest are linking the campaign to the extortion group Clop.
ReliaQuest has documented a JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security vulnerability in PTC Windchill and FlexPLM. Both products are enterprise software for Product Lifecycle Management (PLM) — systems for managing design data, technical drawings and product information throughout the entire development process. According to the researchers’ assessment, this is not a generic web shell but a component specifically designed for the PLM software environment.
ReliaQuest describes the tool as a fully-featured extortion platform: it is capable of mapping sensitive data vaults within the Windchill/FlexPLM environment and decrypting credentials. The attack thus targets not merely individual systems, but specifically the structured engineering and product data that PLM platforms typically distribute and reference across company boundaries and supplier chains.
For CISOs at organizations running PLM deployments, this creates a dual risk: on one hand, the classic data exfiltration with extortion potential; on the other, the loss of confidentiality of intellectual property and design data that are central to competitiveness and supply chain integrity. The connection to Clop, a group with a history of large-scale data extortion campaigns via software vulnerabilities, points to systematic, presumably automatable and scalable exploitation of affected Windchill and FlexPLM installations.
CISOs operating PTC Windchill or FlexPLM should verify the patch status of affected systems, review existing logs for unusual JSP file deposits and access to vault directories, and treat credentials managed by the affected servers as potentially compromised. Since the original report does not cite a specific CVE number or version details, it is advisable to cross-check directly with PTC’s security advisories and ReliaQuest’s detailed analyses.
Source: thehackernews.com · Published August 19, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.