Clop ransomware gang builds custom Java web shell to steal PTC Windchill data

Clop ransomware gang builds custom Java web shell to steal PTC Windchill data

The Clop ransomware group has developed a custom Java web shell specifically designed to target PTC Windchill and FlexPLM servers, according to a new report from cybersecurity firm ReliaQuest. Unlike generic web shells repurposed for various attacks, this implant was built with deep knowledge of Windchill's internal architecture, including its APIs, database schema, keystore, and file-vault structure.

The web shell comes with built-in capabilities to decrypt stored credentials, enumerate file repositories, and exfiltrate data. ReliaQuest discovered the tool during intelligence collection and believes it was deployed in recent data theft attacks exploiting CVE-2026-12569, a critical remote code execution vulnerability affecting PTC Windchill.

"This appears to be an application-specific evolution of Clop's established mass-exploitation playbook," ReliaQuest stated in a report shared with BleepingComputer. The researchers emphasized that the implant is not a generic tool but a highly specialized piece of malware tailored to the targeted platforms.

ReliaQuest linked the activity to Clop based on several factors. Extortion emails used in the attacks contain addresses that match those previously seen on the ransomware gang's data leak site. Additionally, the web shell includes X-windchill-req headers that were observed in earlier Clop campaigns. The tactics, techniques, and procedures (TTPs) employed also align with those commonly used by the threat actor.

Clop has a long history of breaching enterprise platforms for data theft and extortion. Previous campaigns targeted Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer file-sharing servers. The MOVEit campaign alone affected more than 2,770 organizations worldwide. As BleepingComputer reported in July, Clop had already targeted exposed PTC Windchill and FlexPLM servers in a data theft extortion campaign, and this new web shell represents a further evolution of their capabilities. The discovery underscores the group's continued focus on exploiting vulnerabilities in enterprise software to steal sensitive data and demand ransoms.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate