Clop Gang Targets Critical PLM Software
Threat actors are exploiting a severe vulnerability in PTC Windchill and FlexPLM to exfiltrate sensitive enterprise product data.
The Clop ransomware group, also known as Cl0p, has turned its focus toward internet-facing PTC Windchill and FlexPLM platforms. By leveraging a critical vulnerability, these operators are conducting a calculated campaign to exfiltrate sensitive product lifecycle data from organizations across the manufacturing and engineering sectors.
Exploitation of Critical Flaws
The campaign centers on the exploitation of CVE-2026-12569, an improper input validation vulnerability within PTC's software suite. This flaw allows unauthorized parties to achieve remote code execution on affected servers. Once access is established, the attackers deploy JSP webshells to maintain persistence and facilitate the systematic theft of internal documents.
ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration.
— ReliaQuest
Coordinated Extortion Tactics
Beyond initial access, the group has adopted a high-volume communication strategy to pressure their victims. Using email accounts that appear to be previously compromised, the threat actors distribute extortion demands to hundreds of employees within a single target organization simultaneously. This tactic mirrors methodologies previously seen during the group's campaign against Oracle EBS, where the attackers rotated through various email addresses to evade automated detection and notification blocking.
- CVE-2026-12569 carries a CVSS severity score of 9.3.
- PTC began releasing security patches for this specific flaw on June 17.
- The U.S. Department of State offers a $10 million reward for information linking the group to foreign governments.
- PTC software is utilized by over 30,000 customers globally, including 1,500 FlexPLM users.
- The MOVEit Transfer campaign attributed to Clop impacted more than 2,770 organizations.
Remediation and Agency Response
Following the emergence of CVE-2026-12569, the Cybersecurity and Infrastructure Security Agency (CISA) included the vulnerability in its Known Exploited Vulnerabilities catalog. Federal agencies were directed to secure their instances within a three-day window. International authorities, including the German Federal Office for Information Security (BSI), have also taken the unusual step of directly contacting affected customers to emphasize the urgency of applying available releasing security patches.
Implications for Product Security
For organizations relying on PLM systems, this campaign underscores the risks inherent in maintaining legacy or unpatched enterprise software with network connectivity. The shift toward targeting high-value repositories like those managed by PTC suggests that attackers are prioritizing data that holds long-term intellectual property value over simple financial disruption. Security teams are encouraged to treat these platforms as critical assets, ensuring they are shielded behind VPNs or trusted access gateways and that rigorous forensic monitoring is in place to identify potential indicators of compromise.
Sources
- BleepingComputer Original source
- added Also reporting
- its Known Exploited Vulnerabilities catalog Also reporting
- releasing security patches Also reporting
Continue Reading
Surveillance Disguised as Privacy Tools
Researchers have uncovered an Iran-linked campaign using fake VPNs and media players to deploy spyware against specific user groups.
Europol Targets The Com Content Ecosystem
Law enforcement has flagged over 4,000 URLs linked to a network that recruits minors for digital extortion and physical violence.
Vatican-Endorsed App Leaks User Profiles
A critical IDOR vulnerability in the Pope's official prayer app has left the personal data of over 700,000 users exposed for months.