Clop Hacks Shell, GE, Philips in 43-Victim PTC Windchill Zero-Day Campaign | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The logo of US giant General Electric is pictured as French Economy and Finance Minister Bruno Le Maire takes part to a meeting with managers and unions at the GE headquarter in Belfort, eastern France, on June 3, 2019.
PATRICK HERTZOG/AFP via Getty Images

The Clop ransomware gang has named Shell, General Electric, and Philips among 43 organizations it claims to have breached in a sweeping campaign exploiting a critical flaw in PTC’s widely used industrial software — and the engineering blueprints, facility test reports, and project plans it stole represent a categorically different kind of loss than the customer-data breaches that typically define ransomware headlines.

Shell — one of the world’s three largest oil and gas companies, with 85,000 employees across more than 70 countries — confirmed on August 14 that it is investigating a “potential incident,” telling BleepingComputer: “We are aware of a potential incident. We are working with our security teams and relevant experts to investigate.” Clop claims to have taken 89 gigabytes from Shell, including engineering drawings, facility testing reports, and project plans. Philips, the Dutch technology conglomerate, confirmed a compromise of “a specific enterprise server related to internal data,” though it said customer environments were unaffected. GE has not publicly commented as of this writing.

Any organization that runs PTC Windchill or FlexPLM — there are more than 30,000 globally — and has not yet applied patches or searched for attack indicators needs to act immediately and treat its environment as potentially compromised back to early June.

How Clop Got In: A Two-Flaw, Zero-Authentication Attack Chain

The vulnerability at the center of this campaign is CVE-2026-12569, a deserialization-of-untrusted-data flaw in PTC Windchill PDMLink and FlexPLM that the National Vulnerability Database scored at a near-perfect 9.8 out of 10 under CVSS v3.1. The score reflects what makes it so dangerous: any attacker with network access to a vulnerable server can exploit it without credentials and without tricking any user into clicking anything.

Clop affiliates did not use CVE-2026-12569 alone. According to a coordinated Unified Threat Advisory published July 22 by Ransom-ISAC alongside eCrime.ch and DEFUSED, attackers chained it with a separate pre-authentication information-disclosure flaw in FlexPLM’s WSDL (Web Services Description Language) endpoint — itself rated CVSS 7.5 — to map the target environment before triggering the deserialization exploit. The pre-attack reconnaissance is fingerprinted by GET requests to /Windchill/rfa/jsp/login/*.jsp?wsdl returning approximately 4,045 bytes — a pattern that defenders can hunt for retroactively in web logs.

Once inside, attackers deployed hex-named JSP webshells — persistent backdoors disguised as normal application files — under the path /Windchill/login/, following naming patterns such as [0-9a-f]{16}.jsp or dpr_<8hex>.jsp. A file-listing artifact named flst.txt was used to enumerate the filesystem. The malicious HTTP request header X-windchill-req: ?x8Fmgow identifies the exploitation phase and appears in web server logs of compromised systems.

Cybersecurity firm ReliaQuest independently confirmed the campaign and noted that post-exploitation behavior follows the same pattern Clop used against Oracle E-Business Suite in 2025: identify a widely deployed enterprise platform holding high-value data, exploit it across as many exposed instances as possible, stage and exfiltrate, then extort.

A Zero-Day Head Start of Weeks

The timeline of this campaign contains a detail that changes the calculus for every PTC customer: Ransom-ISAC assesses with high confidence that Clop affiliates were exploiting CVE-2026-12569 as a zero-day in early June 2026 — weeks before PTC had issued any patch or public warning.

PTC began releasing security patches on June 17, the same day the vulnerability was publicly disclosed. Eight days later — on June 25 — the U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog and ordered federal agencies to secure their Windchill and FlexPLM instances within three days. That eight-day interval from disclosure to KEV listing is unusually fast and reflects the security community’s assessment that exploitation was already widespread before the patch existed.

Germany’s Federal Office for Information Security took the threat seriously enough to contact PTC customers by phone and email in the middle of the night, urging immediate patching — a level of urgency its own staff rarely invokes.

By the time Clop began sending extortion emails around July 20 — with subject lines reading “Windchill PDMLink module serious data leak,” sent from randomly compromised external accounts to hundreds of employees inside targeted organizations — the intrusions were already six or more weeks old. The emails listed Clop’s contact information and are consistent with the group’s established double-extortion playbook: steal, then threaten publication.

As of August 14, Ransom-ISAC observed C2 IP address 79.141.160.78 during an active incident response engagement — meaning at least one victim’s environment remains under active adversary control.

What Makes PLM Data Different

Most ransomware coverage frames stolen data in terms of personal information: Social Security numbers, credit card numbers, medical records — data whose harm can be mitigated by credit monitoring, notification, and regulatory response. What Clop stole from PTC Windchill and FlexPLM environments is different in kind, not just degree.

PTC Windchill PDMLink and FlexPLM are the operational backbone of product development at companies in aerospace, defense, automotive, energy, and medtech — industries where the software’s job is to be the single source of truth for every version of every design. The data these systems hold includes engineering blueprints, bills of materials, manufacturing process documentation, supplier specifications, component tolerances, facility test reports, and regulatory submissions accumulated over years or decades of product development. PTC’s advisory covers aerospace, defense, automotive customers across these sectors.

Unlike a customer database, this data does not expire. A stolen customer record becomes less valuable as accounts are closed and cards are reissued. A stolen engineering blueprint for a turbine component, a pharmaceutical facility layout, or a defense-adjacent design file retains its competitive and strategic value indefinitely — and in the case of companies like GE, it may include technical data subject to International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR). A breach of ITAR-controlled technical data carries mandatory reporting obligations independent of any ransom negotiation.

More than 1,500 brand and retail companies use FlexPLM specifically; confirmed victim sectors in this campaign include manufacturing, automotive, aerospace, and retail/apparel. The campaign spans 43 named organizations across those sectors.

Clop’s Industrialized Extortion Model

Clop — also tracked as Cl0p, Graceful Spider, Chubby Scorpius, FIN11, and Lace Tempest — has spent years refining mass-exploitation extortion into a repeatable industrial process. The gang identifies a critical flaw in widely deployed enterprise software, exploits it simultaneously across every internet-exposed instance it can find, and then launches parallel extortion campaigns against dozens of organizations at once. As Brandon Parsons, threat intelligence manager at Ascent Solutions and a lead author of the Ransom-ISAC advisory, put it: “They don’t really target a specific company, they target a specific zero-day vulnerability and go after it.”

Prior campaigns followed the same pattern: Accellion FTA in 2021 (Shell was also a victim in that breach), GoAnywhere MFT in 2023, MOVEit Transfer in 2023 (affecting more than 2,770 organizations worldwide, per Emsisoft’s analysis), Cleo in 2024, and Oracle E-Business Suite in 2025 — targeting Harvard University, The Washington Post, Logitech, Korean Air, and dozens of others.

Crucially, Clop’s current campaigns involve no file encryption. By stealing data without locking systems, the group avoids triggering the immediate incident response that a ransomware detonation would cause — giving intrusions more time to go undetected and giving attackers more time to exfiltrate. An organization that restores from an offline backup after this breach still faces the threat of stolen data publication.

According to Censys, approximately 80 internet-exposed Windchill instances remained online as of July 20, down from fewer than 100 before the June 17 advisory — with 80% of them hosted in the United States. That means Clop may have had access to a significant proportion of all internet-facing PTC Windchill installations.

The U.S. Department of State has offered a $10 million reward for information linking Clop’s attacks to a foreign government.

What Organizations Should Do Now

Organizations running PTC Windchill or FlexPLM should begin immediately and treat the threat-hunting window as extending back to early June 2026, regardless of when they received an extortion email or first became aware of the campaign.

Specific steps recommended by Ransom-ISAC and ReliaQuest:

Patch immediately. The fix is available for all versions prior to Windchill/FlexPLM 11.0 M030. PTC’s Trust Center advisory provides version-specific patching guidance.

Hunt for webshells. Search the /Windchill/login/ directory for any JSP file matching the patterns [0-9a-f]{16}.jsp, [0-9a-f]{6}.jsp, or dpr_<8hex>.jsp. New shells may be deployed under different names — any unexpected JSP in this path warrants immediate investigation. Patching the CVE does not remove webshells that attackers already planted; active threat hunting is required.

Review web server logs for the malicious request header X-windchill-req: ?x8Fmgow and for GET requests to /Windchill/rfa/jsp/login/*.jsp?wsdl returning ~4,045 bytes (pre-exploitation reconnaissance). PTC’s support article CS473270 contains the full IOC set. Hunt logs back to early June.

Block C2 addresses. Priority addresses include 79.141.160.78 (observed in an active incident as of August 14), 5.180.41.35, and the full C2 list in PTC’s updated support article.

Rotate credentials on any system showing compromise indicators before restoring services. Do not reconnect remediated systems without confirming webshell removal. ReliaQuest’s post-exploitation remediation guidance emphasizes isolating affected servers and collecting forensic artifacts before restoration.

Preserve forensic artifacts from any compromised systems before restoring. If data was exfiltrated and a regulatory reporting obligation applies — particularly if any stored data is export-controlled under ITAR or EAR — consult legal counsel before any public-facing response.


Frequently Asked Questions

What is PTC Windchill, and why does it matter that Clop targeted it?

PTC Windchill PDMLink is one of the most widely deployed product lifecycle management platforms in the world, used by engineering and manufacturing teams at more than 30,000 companies to store and manage product designs, blueprints, test reports, and manufacturing documentation from concept through production. FlexPLM is a related platform used specifically by more than 1,500 retail, footwear, and apparel companies for the same purpose. PLM systems hold years or decades of accumulated intellectual property — not personal data that can be canceled or replaced, but trade secrets and design files that retain strategic and competitive value indefinitely. Targeting a PLM platform is the industrial equivalent of stealing an organization’s entire engineering archive.

My organization patched CVE-2026-12569 — are we safe?

Patching the vulnerability closes the door that Clop used to enter, but it does not remove any webshells attackers may have already deployed. Ransom-ISAC and ReliaQuest both emphasize that threat hunting must accompany patching. Any organization that was running internet-exposed Windchill or FlexPLM instances between early June and the application of the patch should search the /Windchill/login/ directory for unexpected JSP files and review web logs for the malicious X-windchill-req: ?x8Fmgow header and pre-attack reconnaissance patterns.

Why is Clop sending extortion emails to hundreds of individual employees instead of just contacting the company?

This tactic is deliberate pressure amplification. By emailing hundreds of staff at a victim organization simultaneously — using subject lines like “Windchill PDMLink module serious data leak” sent from randomly compromised external accounts — Clop creates internal awareness of the breach that management may not have disclosed, increasing the psychological and reputational pressure on decision-makers to pay. It is consistent with the group’s established playbook observed in prior campaigns, which Ransom-ISAC previously documented during Clop’s Oracle EBS campaign.

How is Clop different from typical ransomware groups?

Clop does not deploy file-encrypting ransomware in its recent campaigns. Instead, it focuses entirely on data theft — stealing sensitive files and threatening to publish them publicly on its dark web leak site unless victims pay. This means victims experience no system outage or visible disruption at the time of the breach, which can delay detection significantly. An organization that successfully restores from a clean backup after this type of attack still faces the threat of its stolen engineering data being published or sold. The group’s extortion approach targets software platforms used across many organizations simultaneously rather than selecting specific companies as targets.

——————————————————–


Click Here For The Original Source.

.........................