Clop has been using a custom web shell built specifically for PTC’s Windchill and FlexPLM product lifecycle management software, and researchers say the fallout is still spreading. The ransomware group, which began mass-exploitation campaigns in June, has claimed data from more than 40 organizations, many of them large manufacturers, aerospace firms, and automotive companies.
The intrusion path starts with CVE-2026-12569, a 9.3-rated input-validation flaw that allows remote code execution through a crafted request. What follows is not the usual lightweight shell: ReliaQuest says the implant decrypts every credential in the Windchill keystore, maps vault contents for exfiltration, and ships a custom Java class loader to run further code, turning it into a full remote-access platform.
ReliaQuest described the tool as a direct path to credential theft and large-scale data exfiltration that needs no additional tooling, since the shell delivers malware, decrypts secrets, and maps stored files on its own. Attribution to Clop comes from Ransom-ISAC, eCrime.ch, and Defused.
Clop began emailing victims in mid-July with pay-or-leak deadlines, and companies are still hunting for signs of compromise. The campaign follows the group’s pattern of exploiting one popular enterprise product at scale, as it did with MOVEit and GoAnywhere. PLM administrators should treat any Windchill exposure as a priority and review keystore and vault access logs for the JSP implant.
