Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Cybersecurity News
  5. Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

Scheduled Pinned Locked Moved Cybersecurity News
1 Posts 1 Posters 35 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Title: Clop-Attributed Web Shell Targets PTC Windchill, Engineered for Data Exfiltration and Extortion

    Summary:
    New analysis from ReliaQuest has detailed a JSP web shell deployed against PTC Windchill and FlexPLM servers. The tool appears purpose-built for enterprise PLM environments, enabling credential decryption and systematic mapping of engineering vaults as part of an extortion-focused campaign linked to the Clop ransomware group.

    Body:
    Recent research from ReliaQuest has shed light on the operational capabilities of a JSP-based web shell observed following the exploitation of a critical vulnerability in PTC Windchill and FlexPLM servers. The shell is not a generic backdoor but a highly specialized tool tailored for enterprise Product Lifecycle Management (PLM) infrastructure.

    The malware is described as a fully featured extortion platform. Its core functions include decrypting stored credentials and mapping sensitive vault data, which typically contains proprietary engineering files, CAD drawings, and other intellectual property central to manufacturing and design workflows. This level of specificity suggests the threat actors have a deep understanding of the target environment’s data hierarchy.

    Given the destructive potential and the focus on high-value industrial data, the deployment is attributed to Clop, a ransomware group known for leveraging zero-day vulnerabilities in file transfer and enterprise software to conduct mass data theft and subsequent blackmail campaigns.

    Security teams running PTC Windchill or FlexPLM environments are advised to review their server logs for unauthorized JSP file writes and to audit access to credential stores. The original report from ReliaQuest provides additional indicators of compromise and technical details.

    Source: Original analysis by ReliaQuest, as reported by The Hacker News.
    URL: https://thehackernews.com/2026/08/clop-linked-windchill-web-shell.html

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World