Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
Executive Summary
A JSP web shell linked to the Clop ransomware group was deployed after exploiting a critical flaw in PTC Windchill and FlexPLM servers. The shell decrypts stolen credentials and maps engineering data, turning the PLM environment into an extortion platform.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-19T05:39:25+00:00 - Category: threat-intel
Original Description: A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest. The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault
"Arriving at one point is the starting point to another."
— John Dewey