Home / Aug 19, 2026 / Story
0
#2 BleepingComputer general August 18, 2026 at 17:29 UTC

Clop created custom web shell for Windchill data theft attacks

By Lawrence Abrams

AI Summary

A custom Java web shell, likely developed by the Clop ransomware gang, was purpose-built to target PTC Windchill and FlexPLM product lifecycle management servers, with built-in functionality to decrypt stored credentials, enumerate file repositories, and exfiltrate data. This represents a significant escalation in Clop's tooling sophistication, moving beyond generic exploitation to industry-specific implants. Organizations running Windchill or FlexPLM should treat these servers as high-priority targets and audit for indicators of compromise.

Relevance score: 87.0/100

# More from August 19