The Unified Threat Advisory is a coordinated Cyber Intelligence effort led by Ransom-ISAC, with collaboration from eCrime.ch and DEFUSED. This update covers active Cl0p ransomware affiliate exploitation targeting internet-exposed PTC Windchill and FlexPLM deployments.
Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling unauthenticated remote code execution and deployment of hex-named JSP webshells under /Windchill/login/ . Post-exploitation includes filesystem enumeration via flst.txt , staging of engineering/design data, and double-extortion data theft. Confirmed victim sectors include Manufacturing, Automotive, Aerospace, and Retail/Apparel.
This advisory issues four new C2 indicators alongside previously distributed IOCs from 7/8/2026, 7/1/2026, 6/25/2026, and 6/18/2026.
PTC has released fixed builds for both defects; unpatched, internet-exposed Windchill/FlexPLM instances remain the primary attack surface.
On 20 July, Ransom-ISAC began observing an alleged Cl0p ransomware (aka Graceful Spider, Chubby Scorpius, FIN11, Lace Tempest) data extortion campaign sending emails with a subject line, “Windchill PDMLink module serious data leak” to an unknown number of affected organizations (Figure 1 & Figure 2). The extortion emails appear to originate from randomly compromised accounts, are sent to hundreds of users within an impacted organization and include Cl0p’s latest information (Figure 3). This extortion approach is consistent with what we observed with the Oracle EBS campaign last year, except for the use of new email addresses.
Figure 1: Extortion email sent to employees across the victim organization, claiming Cl0p has breached the company and attributing the compromise to its PTC Windchill software.
Figure 2: A further extortion email to the same recipients, reinforcing the breach claim and the attribution to PTC Windchill to intensify pressure — publicly confirming the link to the Windchill campaign.
Figure 3: Update posted to Cl0p’s dedicated data leak site listing the new email addresses victims are directed to use for .
We suspect that threat actors affiliated with Cl0p ransomware most likely exploited CVE-2026-12569 as a zero-day vulnerability in early June 2026. CVE-2026-12569 (CVSS v3.1 9.8 / 10; vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H ) was disclosed on 17 June, 2026 and is described as a critical-severity remote code execution (RCE) vulnerability in PTC Windchill PDMlink and PTC FlexPLM that may be exploited through the deserialization of untrusted data. CVE-2026-12569 also impacts Windchill and FlexPLM releases prior to 11.0 M030. CISA added CVE-2026-12569 to their known exploited vulnerabilities (KEV) catalog on 25 June, 2026. In the observed intrusions, this RCE is chained with a separate pre-authentication information-disclosure defect in the FlexPLM WSDL endpoint (CVSS v3.1 7.5) to enable unauthenticated exploitation.
The following indicators reflect the expanded set published in PTC’s advisory (CS473270) as of its 7/27/2026 update and re-synced against the advisory on 2026-08-14, and are provided in addition to the indicators listed above. As always, validate network indicators against your own environment before blocking — some may correspond to shared or ephemeral hosting.
PTC published the following MD5 hashes associated with the campaign:
The following indicator was encountered by Ransom-ISAC during an active incident response engagement, separate from PTC’s published advisory. Treat it as a high-confidence command-and- control address and block at the perimeter.
Organizations receiving emails matching this pattern should conduct threat hunting dating back to early June 2026, using the indicators of compromise (IOCs) in PTC’s advisory as soon as possible and follow PTC’s remediation steps outlined in PTC’s Support Article . This situation is still developing.
We will continue to monitor for any updates with this latest campaign. As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
