Ethical Hacking News
Cl0p, a notorious hacking group, has recently targeted over 40 organizations through a vulnerability in PTC's Windchill and FlexPLM platforms. This exploit takes advantage of a critical remote code execution (RCE) vulnerability, CVE-2026-12569, which has a CVSS score of 9.3. The group's modus operandi is to exploit one flaw in enterprise software to attack many companies, then publish the victims' names if they refuse to pay. This is not a new pattern for Cl0p, as the group has run this same mass-exploitation-then-extortion model repeatedly against various targets in the past. The group's tooling goes well beyond a basic web shell, using a custom implant to steal data and maintain access to the compromised systems. The stolen data includes sensitive corporate files, databases, and engineering documents, highlighting the importance of protecting enterprise software and data. If your organization runs Windchill or FlexPLM, make sure to check for this specific CVE and apply the necessary patches as soon as possible to avoid falling victim to Cl0p's campaign.
Over 40 organizations targeted through a vulnerability in PTC's Windchill and FlexPLM platforms. Cl0p's modus operandi involves exploiting a single flaw in enterprise software to attack many companies and then publishing their names if they refuse to pay. The vulnerability (CVE-2026-12569) has a CVSS score of 9.3 and impacts all CPS versions and Windchill and FlexPLM releases prior to 11.0 M030. Cl0p deployed a custom implant that allows for full data theft with no additional tools required. The stolen data includes databases, project files, backups, engineering documents, and corporate files. The victim list includes major manufacturing and industrial names, with some organizations acknowledging awareness of the claims. Cl0p's campaign highlights the importance of staying vigilant and up-to-date with the latest security patches and vulnerabilities.
Cl0p, a notorious hacking group, has recently targeted over 40 organizations through a vulnerability in PTC's Windchill and FlexPLM platforms. This exploit takes advantage of a critical remote code execution (RCE) vulnerability, CVE-2026-12569, which has a CVSS score of 9.3. The group's modus operandi is to exploit one flaw in enterprise software to attack many companies, then publish the victims' names if they refuse to pay. This is not a new pattern for Cl0p, as the group has run this same mass-exploitation-then-extortion model repeatedly against various targets in the past.
The vulnerability in question impacts all CPS versions and Windchill and FlexPLM releases prior to 11.0 M030. An attacker can exploit this vulnerability through the deserialization of untrusted data. German police reportedly warned organizations directly that attacks were coming, which tells you the exploitation window here wasn’t exactly subtle to security researchers watching it unfold.
Cl0p's tooling for this campaign goes well beyond a basic web shell. Security firm ReliaQuest found that the group deployed a custom implant built for full data theft on its own, no additional tools required to actually pull data out once inside. A class loader like this turns a single web shell into an open-ended backdoor, useful for lateral movement, ransomware deployment, or just quietly sitting there for months.
The web shell gives attackers a direct path to credential theft and large-scale data exfiltration, with no additional tooling required. Unlike generic command shells, this implant decrypts credentials, delivers malware, and maps stored files for exfiltration. The stolen data includes databases, project files, backups, engineering documents, blueprints, diagrams, and corporate files, as well as images.
The victim list reads like a cross-section of major manufacturing and industrial names, including Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, and Largan Precision. Researchers noticed that GE was on the list briefly before quietly disappearing from Cl0p's site, a move that usually signals either a ransom payment or at least resumed negotiations behind closed doors. Shell, Philips, Fiserv, and GE have all publicly acknowledged awareness of the claims and said they’re investigating, though none has confirmed a significant breach so far.
This is not a new pattern for Cl0p specifically; it’s the same mass-exploitation-then-extortion model the group has run repeatedly against various targets in the past. What’s different this time is the target: enterprise PLM software sits deep inside manufacturing supply chains, holding the exact kind of engineering data that competitors and nation-states alike would pay real money to see.
If your organization runs Windchill or FlexPLM and hasn’t checked for this specific CVE yet, that’s the item to move to the top of today’s list. The group's naming strategy followed its usual slow build. The group initially posted partial company names on its leak site, then switched to full names starting August 12, and the victim count has climbed steadily since. For each organization, the listing includes what type of data got stolen and roughly how much, ranging anywhere from a single gigabyte up to multiple terabytes depending on the target.
The stolen data includes databases, project files, backups, engineering documents, blueprints, diagrams, and corporate files, as well as images. The web shell gives attackers a direct path to credential theft and large-scale data exfiltration, with no additional tooling required. Unlike generic command shells, this implant decrypts credentials, delivers malware, and maps stored files for exfiltration.
Cl0p's campaign highlights the importance of staying vigilant and up-to-date with the latest security patches and vulnerabilities. If you're running Windchill or FlexPLM, make sure to check for this specific CVE and apply the necessary patches as soon as possible.
Related Information:
https://www.ethicalhackingnews.com/articles/Cl0ps-PTC-Windchill-Exploit-A-Threat-to-Enterprise-Security-and-Data-Integrity-ehn.shtml
https://securityaffairs.com/197587/cyber-crime/cl0p-targets-40-organizations-through-ptc-windchill-flaw.html
https://www.securityweek.com/cl0p-ransomware-group-names-over-40-victims-of-ptc-windchill-campaign/
https://en.wikipedia.org/wiki/Clop_(hacker_group)
https://deepstrike.io/blog/cl0p-ransomware
Published: Fri Aug 21 03:54:01 2026 by llama3.2 3B Q4_K_M