Actor Profile
Clop (also tracked as Cl0p) is a financially motivated cybercrime group specializing in data theft extortion campaigns. The gang systematically targets enterprise software platforms with exposed Internet-facing instances, exploiting vulnerabilities to exfiltrate sensitive data and extort victims by threatening to publish stolen information on their dark web leak site. Clop operates with a consistent playbook: identify zero-day or recently disclosed vulnerabilities in widely deployed enterprise applications, exploit them at scale, and conduct mass extortion using compromised email accounts to contact multiple employees within victim organizations. The U.S. Department of State offers a $10 million reward for information linking Clop's operations to a foreign government.
TTPs (Tactics, Techniques, Procedures)
Clop exploits CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) in PTC Windchill and FlexPLM, enabling unauthenticated remote code execution (T1190 - Exploit Public-Facing Application). The gang deploys JSP webshells for persistent access and remote command execution (T1505.003 - Server Software Component: Web Shell), then exfiltrates sensitive product lifecycle management data (T1567 - Exfiltration Over Web Service). For extortion, Clop uses previously compromised email accounts to send mass extortion messages to hundreds of employees within targeted organizations (T1566 - Phishing for initial contact, though emails are sent post-compromise). The group changes email addresses between campaigns to evade detection and maintain operational security. Stolen data is published on Clop's dark web leak site via Torrent if ransom demands are not met (T1486 - Data Encrypted for Impact, though focus is data theft rather than encryption).
Targets & Patterns
Clop targets organizations in manufacturing, aerospace, defense, automotive, heavy machinery, retail, and medtech sectors—industries that rely heavily on Product Lifecycle Management (PLM) platforms like PTC Windchill and FlexPLM. These systems contain highly sensitive intellectual property, including product designs, engineering specifications, supply chain data, and proprietary manufacturing processes. PTC reports over 30,000 customers globally, with more than 1,500 using FlexPLM, representing a substantial attack surface. Clop specifically seeks Internet-exposed instances of enterprise applications that handle high-value data repositories, allowing for mass exploitation and maximum extortion leverage. The gang's targeting pattern focuses on widely deployed enterprise software with critical vulnerabilities, enabling them to compromise multiple organizations simultaneously and maximize financial return through data theft extortion rather than traditional ransomware encryption.
Historical Context
This campaign continues Clop's established pattern of exploiting vulnerabilities in enterprise file-sharing and data management platforms. Previous campaigns include: Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and the MOVEit Transfer campaign that affected over 2,770 organizations worldwide. Most recently, Clop exploited an Oracle EBS zero-day flaw starting in August 2025, compromising Harvard University, The Washington Post, GlobalLogic, University of Pennsylvania, Logitech, Estée Lauder, Korean Air, and American Airlines subsidiary Envoy Air. The current Windchill/FlexPLM campaign shares tradecraft characteristics with the Oracle EBS operation, including the use of compromised email accounts for mass extortion messaging sent to hundreds of employees per organization. Clop's operational pattern involves changing email addresses before launching new campaigns, maintaining OPSEC while recycling proven tactics. A similar critical Windchill/FlexPLM vulnerability (CVE-2026-4681) prompted emergency German government response in March 2026, indicating ongoing threat actor interest in these PLM platforms.
Defensive Recommendations
- Immediately patch PTC Windchill and FlexPLM systems against CVE-2026-12569 (CVSS 9.3) following vendor guidance released June 17, 2026; CISA has added this to the KEV catalog requiring federal agency remediation within three days
- Remove PTC Windchill and FlexPLM instances from direct Internet exposure; place behind VPNs or zero-trust access gateways to prevent unauthenticated exploitation (mitigates T1190)
- Hunt for JSP webshells in Windchill/FlexPLM web directories; monitor for suspicious .jsp file creation, unusual outbound connections, and abnormal data exfiltration patterns (detects T1505.003)
- Review PTC advisory IOCs and collect forensic artifacts from suspected compromised servers; isolate affected systems immediately and rotate all credentials with access to PLM platforms before restoration
- Monitor for mass extortion emails originating from external compromised accounts sent to multiple employees; implement email security controls to detect bulk messaging patterns consistent with Clop's post-exploitation extortion tactics
