Cybercriminals associated with the Cl0p ransomware group are actively targeting vulnerabilities in PTC's Windchill and FlexPLM software as part of a new data extortion campaign. These attackers exploit specific flaws that allow unauthenticated remote code execution, which they use to deploy malicious web shells. This tactic enables them to steal sensitive data from targeted organizations. The campaign primarily affects sectors such as manufacturing, automotive, aerospace, and retail, exploiting a critical security vulnerability identified as CVE-2026-12569 with a CVSS score of 9.3. This flaw was recently added to the U.S. Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog. PTC has acknowledged ongoing threat activity against its systems, warning customers about these exploits. Indicators of compromise have been shared by Ransom-ISAC to aid in detection efforts. The threat actors use compromised accounts to send extortion emails to numerous users within affected organizations, leveraging the stolen data for extortion. This campaign mirrors past Cl0p operations that have targeted enterprise software vulnerabilities to gain unauthorized access and exfiltrate valuable data.
Cl0p Ransomware Exploits Critical Vulnerabilities in PTC Software
Cl0p affiliates exploit unauthenticated RCEs in Windchill and FlexPLM to steal data for extortion campaigns.


