#2
BleepingComputer
general
August 18, 2026 at 17:29 UTC
Clop created custom web shell for Windchill data theft attacks
By Lawrence Abrams
AI Summary
A custom Java web shell, likely developed by the Clop ransomware gang, was purpose-built to target PTC Windchill and FlexPLM product lifecycle management servers, with built-in functionality to decrypt stored credentials, enumerate file repositories, and exfiltrate data. This represents a significant escalation in Clop's tooling sophistication, moving beyond generic exploitation to industry-specific implants. Organizations running Windchill or FlexPLM should treat these servers as high-priority targets and audit for indicators of compromise.
Relevance score: 87.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →