CVE Tools

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

The Hacker NewsBy The Hacker News

Reported exploitedWindchillCl0pFlexPLM

Our summary

ReliaQuest researchers have identified a bespoke JavaServer Pages (JSP) web shell associated with the Clop ransomware operation, targeting PTC Windchill and FlexPLM servers. This implant exploits CVE-2026-12569, a critical vulnerability allowing remote code execution, to establish persistent access within the application.

Unlike generic shells, this tool is specifically engineered to interact with PLM software, enabling attackers to decrypt administrative and LDAP credentials directly from the Windchill keystore. By leveraging the application's own database identities, the malware facilitates the rapid exfiltration of sensitive engineering data and product designs while evading standard signature-based detection.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store