Cybersecurity experts have uncovered a new wave of attacks linked to the Cl0p ransomware group, with threat actors exploiting critical vulnerabilities in internet-facing PTC Windchill and FlexPLM systems to steal sensitive corporate data and carry out extortion campaigns.
A coordinated security advisory issued by Ransom-ISAC, eCrime.ch, and DEFUSED warns that attackers are chaining multiple vulnerabilities to gain unauthenticated remote code execution (RCE) on exposed servers, allowing them to compromise enterprise environments without valid login credentials.
Critical Vulnerabilities Enable Remote Access
According to researchers, attackers first exploit a pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint before leveraging a server-side vulnerability in the Windchill login servlet. This attack chain enables remote code execution and the deployment of malicious JSP web shells within affected systems.
The implanted web shells provide attackers with persistent remote access, enabling them to execute commands, browse files, and prepare stolen information for exfiltration.
Manufacturing and Aerospace Firms Among Primary Targets
The campaign has primarily targeted organizations operating in:
- Manufacturing
- Automotive
- Aerospace
- Retail
Once attackers gain access, they reportedly perform extensive file system reconnaissance, collect engineering and product design files, and exfiltrate valuable intellectual property before launching extortion attempts.
Researchers say the attackers are following a double extortion strategy, stealing confidential information before threatening to publicly release it unless a ransom is paid.
Exploitation Linked to Critical CVE-2026-12569
Security analysts believe the attacks are exploiting CVE-2026-12569, a critical vulnerability affecting PTC Windchill that carries a CVSS score of 9.3.
The flaw was recently added to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog, highlighting evidence of active exploitation in real-world attacks.
PTC has also confirmed receiving multiple reports of increased threat activity, warning customers that attackers are deploying JSP web shells on vulnerable installations.
Researchers further noted that the Windchill vulnerability is being combined with a separate FlexPLM information disclosure flaw (CVSS 7.5), enabling complete unauthenticated compromise of exposed systems.
Indicators of Compromise Released
To help organizations identify potential intrusions, researchers published four IP addresses associated with the campaign:
- 216.152.148.54
- 216.152.151.204
- 104.243.35.63
- 5.180.41.35
These indicators match those previously released by PTC during its security advisory.
Extortion Emails Sent from Compromised Accounts
Following data theft, victims reportedly receive extortion emails sent from previously compromised corporate email accounts.
The messages are often distributed to hundreds of employees within the affected organization and include instructions for contacting the Cl0p ransomware operators to negotiate payment.
ReliaQuest Observes Active Exploitation
Cybersecurity firm ReliaQuest has also confirmed ongoing exploitation of CVE-2026-12569.
According to the company, attackers are using the vulnerability to execute remote commands, install JSP web shells, and steal highly sensitive product and engineering data from compromised organizations.
Although investigators have not officially attributed the campaign to a specific threat actor, the tactics, techniques, and procedures closely resemble previous operations conducted by the Cl0p ransomware group.
Cl0p Continues Targeting Enterprise Software
The Cl0p ransomware operation has built a reputation for exploiting vulnerabilities in widely deployed enterprise applications to conduct large-scale data theft campaigns.
Previous attacks linked to the group have targeted products such as:
- Accellion FTA
- GoAnywhere MFT
- MOVEit Transfer
- Cleo file transfer software
- SolarWinds Serv-U FTP
- Oracle E-Business Suite
Security experts recommend that organizations immediately apply available security updates, restrict internet exposure of vulnerable systems, monitor for published indicators of compromise, and investigate any signs of unauthorized JSP web shell activity to reduce the risk of compromise.