Ethical Hacking News
Cybersecurity experts have been warning about the growing threat landscape for some time now, with a recent campaign by the Cl0p gang targeting internet-exposed PTC Windmill and FlexPLM deployments with unauthenticated RCE. This attack highlights the need for organizations to stay vigilant and proactive when it comes to maintaining the security of their networks.
The Cl0p gang has been linked to multiple ransomware campaigns targeting enterprise applications and high-value data repositories. The group exploits security flaws in widely-used products before gaining initial access into a target organization's network. Their latest campaign exploited CVE-2026-12569, a critical security flaw in PTC Windmill, to gain unauthenticated remote code execution and deployment of hex-named JSP web shells. The attackers conduct file system enumeration, stage engineering/design data, and ultimately carry out double extortion data theft. The campaign targets manufacturing, automotive, aerospace, and retail sectors, with four IP addresses shared as indicators of compromise.
The world of cybersecurity is continually evolving, with new threats emerging every day. In recent times, a group of threat actors known as the Cl0p (also referred to as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) has been making headlines for their malicious activities. This article will delve into the specifics of their latest attack campaign, which targeted internet-exposed PTC Windmill and FlexPLM deployments with unauthenticated remote code execution (RCE). This attack highlights the growing sophistication and complexity of modern cybersecurity threats.
The Cl0p gang, also known as the "Cl0p Affiliates," has been linked to a number of previous ransomware campaigns targeting enterprise applications and high-value data repositories. Their tactics typically involve exploiting security flaws in widely-used products before gaining initial access into a target organization's network. Once inside, they carry out file system enumeration, stage engineering/design data, and ultimately conduct double extortion data theft.
Their latest campaign was triggered by the exploitation of CVE-2026-12569, a critical security flaw in PTC Windmill that was recently added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog late last month. According to information released by Ransom-ISAC along with eCrime.ch and DEFUSED, attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling unauthenticated remote code execution and deployment of hex-named JSP web shells under /Windchill/login/. This flaw has been given a CVSS score of 9.3.
Upon gaining initial access, attackers conduct file system enumeration, stage engineering/design data, and ultimately carry out double extortion data theft. Targets of the campaign include manufacturing, automotive, aerospace, and retail sectors. The attackers are believed to be exploiting other vulnerabilities in addition to CVE-2026-12569, although no further details have been released.
Ransom-ISAC has shared four IP addresses as indicators of compromise (IoCs), all of which match those shared by PTC - 216.152.148.54, 216.152.151.204, 104.243.35.63, and 5.180.41.35. The extortion emails appear to originate from previously compromised accounts and are sent to hundreds of users within an impacted organization, along with ways to contact the Cl0p ransomware crew.
In a separate post on X, ReliaQuest said it observed threat actors actively exploiting CVE-2026-12569 to facilitate "unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration." The actor behind these attacks remains unconfirmed. However, the observed tradecraft shares characteristics with previous Cl0p campaigns targeting enterprise applications and high-value data repositories.
The Cl0p gang has a storied history of going after security flaws in widely-used enterprise products to break into target organizations for data theft and extortion attacks. Previous campaigns mounted by the group have weaponized file transfer appliances, including those from Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer, as well as a vulnerability in Oracle E-Business Suite.
The increasing sophistication of cybersecurity threats such as the Cl0p campaign highlights the need for organizations to stay vigilant and proactive when it comes to maintaining the security of their networks. As new vulnerabilities are discovered and exploited by threat actors, it is essential that companies take immediate action to patch these flaws and implement robust security measures to protect themselves from potential attacks.
Related Information:
https://www.ethicalhackingnews.com/articles/The-Increasingly-Complex-Threat-Landscape-Cl0p-Affiliates-Target-Internet-Exposed-PTC-Windchill-and-FlexPLM-with-Unauthenticated-RCE-ehn.shtml
https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html
https://nvd.nist.gov/vuln/detail/CVE-2026-12569
https://www.cvedetails.com/cve/CVE-2026-12569/
Published: Sat Jul 25 07:49:22 2026 by llama3.2 3B Q4_K_M