Actor Profile
Cl0p (also tracked as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) is a financially-motivated ransomware operation known for systematically exploiting zero-day and N-day vulnerabilities in enterprise file transfer and business-critical applications. The group specializes in mass exploitation campaigns targeting internet-exposed systems, followed by data theft and double extortion tactics. Cl0p has established a pattern of weaponizing vulnerabilities in widely-deployed enterprise software to maximize victim reach and leverage high-value data for extortion.
TTPs (Tactics, Techniques, Procedures)
The campaign leverages an exploit chain combining pre-authentication information disclosure in FlexPLM WSDL endpoints (CVSS 7.5) with CVE-2026-12569 (CVSS 9.3), a critical server-side flaw in PTC Windchill login servlets, to achieve unauthenticated remote code execution. Post-exploitation TTPs include: deployment of hex-named JSP web shells under /Windchill/login/, file system enumeration, staging of engineering and design data, and double extortion data theft. Extortion emails are sent from previously compromised accounts to hundreds of users within victim organizations. The attack pattern aligns with T1190 (Exploit Public-Facing Application), T1505.003 (Web Shell), T1083 (File and Directory Discovery), T1074 (Data Staged), and T1567 (Exfiltration Over Web Service).
Targets & Patterns
The campaign primarily targets organizations in manufacturing, automotive, aerospace, and retail sectors that deploy internet-exposed PTC Windchill and FlexPLM instances. These Product Lifecycle Management (PLM) systems contain high-value intellectual property, engineering designs, and proprietary product data, making them attractive targets for data extortion. The focus on PLM platforms reflects Cl0p's strategic targeting of enterprise applications that store sensitive business-critical information with significant financial and competitive value. The mass exploitation approach suggests opportunistic targeting of any vulnerable internet-facing instance rather than highly selective victim profiling.
Historical Context
This campaign continues Cl0p's established operational pattern of exploiting vulnerabilities in enterprise file transfer and business applications. Previous Cl0p campaigns have weaponized flaws in Accellion FTA (2020-2021), GoAnywhere MFT (2023), MOVEit Transfer (CVE-2023-34362, widespread exploitation in 2023), SolarWinds Serv-U FTP, Cleo file transfer products, and Oracle E-Business Suite. The PTC Windchill campaign represents the group's ongoing evolution in targeting enterprise software ecosystems, maintaining their focus on applications that facilitate access to large volumes of sensitive corporate data suitable for extortion. CVE-2026-12569 was added to CISA's KEV catalog in June 2026, indicating active exploitation prior to this campaign's public disclosure.
Defensive Recommendations
- Immediately patch PTC Windchill and FlexPLM to versions addressing CVE-2026-12569 and the FlexPLM WSDL information disclosure flaw; prioritize internet-exposed instances
- Block IoCs at network perimeter: 216.152.148.54, 216.152.151.204, 104.243.35.63, 5.180.41.35
- Hunt for hex-named JSP files under /Windchill/login/ directories and unusual servlet activity in PTC application logs indicating T1505.003 web shell deployment
- Implement network segmentation to isolate PLM systems from direct internet exposure; require VPN or zero-trust access controls for remote access to Windchill/FlexPLM
- Monitor for anomalous outbound data transfers from PLM systems and enable logging for file enumeration activity (T1083) and data staging operations (T1074)
- Review email logs for mass-sent extortion messages originating from compromised internal accounts as an indicator of successful breach
