Cl0p Ransomware Group Exploits PTC Windchill and FlexPLM Vulnerabilities in New Data Extortion Campaign
The notorious **Cl0p** ransomware group, also known by aliases such as **Chubby Scorpius** and **Lace Tempest**, is actively exploiting critical vulnerabilities in internet-exposed **PTC Windchill** and **FlexPLM** deployments. This latest campaign targets manufacturing, automotive, aerospace, and retail sectors, leveraging chained flaws for unauthenticated remote code execution and double extortion data theft.

Threat actors linked to the **Cl0p** ransomware campaign are exploiting flaws in internet-exposed **PTC Windchill** and **FlexPLM** deployments as part of a new data extortion campaign.
### Chained Vulnerabilities Lead to RCE
According to a new coordinated advisory released by **Ransom-ISAC** along with **eCrime.ch** and **DEFUSED**, attackers are chaining a pre-authentication information disclosure in the **FlexPLM WSDL** endpoint with a server-side flaw in the **Windchill** login servlet. This combination enables unauthenticated remote code execution and the deployment of hex-named **JSP** web shells under `/Windchill/login/`.
Upon gaining an initial foothold, the attackers conduct file system enumeration, stage engineering/design data, and ultimately carry out double extortion data theft. Targets of the campaign include manufacturing, automotive, aerospace, and retail sectors.
### CVE-2026-12569: A Critical Flaw
It's suspected that threat actors are exploiting **CVE-2026-12569** (CVSS score: 9.3), a critical security flaw in **PTC Windchill** that was added to the U.S. **Cybersecurity and Infrastructure Security Agency's (CISA)** Known Exploited Vulnerabilities (**KEV**) catalog late last month.
**PTC** warned customers in an advisory that it had "received continued reports of heightened threat activity," adding that unknown attackers are exploiting the vulnerability to deploy **JSP** web shells against susceptible systems.
Researchers Brandon Parsons, Corsin Camichel, and Simo Kohonen noted, "In the observed intrusions, this RCE is chained with a separate pre-authentication information-disclosure defect in the **FlexPLM WSDL** endpoint (CVSS v3.1 7.5) to enable unauthenticated exploitation."

### Indicators of Compromise (IoCs)
**Ransom-ISAC** has shared four IP addresses as indicators of compromise (**IoCs**), all of which match those shared by **PTC**:
* 216.152.148.54
* 216.152.151.204
* 104.243.35.63
* 5.180.41.35
The extortion emails appear to originate from previously compromised accounts and are sent to hundreds of users within an impacted organization, along with instructions to contact the **Cl0p** ransomware crew.
### Cl0p's History of Exploitation
In a separate post on **X**, **ReliaQuest** observed threat actors actively exploiting **CVE-2026-12569** to facilitate "unauthenticated remote code execution and **JSP** web shell deployment for remote command execution and sensitive product data exfiltration."
While the actor behind these attacks remains unconfirmed, the observed tradecraft shares characteristics with previous **Cl0p** campaigns targeting enterprise applications and high-value data repositories. The **Cl0p** gang has a storied history of targeting security flaws in widely-used enterprise products to breach organizations for data theft and extortion. Previous campaigns have weaponized file transfer appliances, including those from **Accellion FTA**, **GoAnywhere MFT**, **SolarWinds Serv-U FTP**, **Cleo**, and **MOVEit Transfer**, as well as a vulnerability in **Oracle E-Business Suite**.