Clop created custom web shell for Windchill data theft attacks

Cybersecurity Threat Actors Create Custom Web Shell to Steal Data from PTC Windchill Servers

A sophisticated cyber threat has been uncovered, with hackers leveraging a custom-built web shell to steal sensitive data from PTC Windchill servers. The web shell, linked to the notorious Clop ransomware gang, is specifically designed to exploit vulnerabilities in these servers and exfiltrate valuable information.

The custom Java web shell was analyzed by cybersecurity company ReliaQuest after it was deployed in recent attacks exploiting CVE-2026-12569, a critical remote code execution vulnerability affecting PTC Windchill. What sets this web shell apart from others is its tailored design to work with the internal APIs, database schema, keystore, and file-vault structure of Windchill servers. This level of specificity suggests that the threat actors have extensive knowledge of Windchill’s inner workings.

This is not an isolated incident; ReliaQuest notes that this appears to be a targeted evolution of Clop’s established playbook for mass exploitation. The researchers found evidence linking the web shell to Clop, including extortion emails containing addresses used on the gang’s data leak site and previously observed X-windchill-req headers.

Clop has a long history of breaching enterprise platforms in data theft attacks, targeting various file-sharing servers, including Accellion FTA, GoAnywhere MFT, SolarWinds Serv-U FTP, Cleo, and MOVEit Transfer. The group’s latest campaign, which began in July, involved exploiting CVE-2026-12569 to deploy JSP web shells on exposed PTC Windchill and FlexPLM servers.

The custom web shell’s capabilities are designed to facilitate the theft of sensitive data from Windchill servers. It can decrypt stored credentials, enumerate file repositories, and steal files, all while blending in with the server’s normal activity. The researchers explain that the web shell connects to Windchill’s database using its own classes, making it difficult for security teams to detect.

The web shell is controlled through a custom protocol sent via the HTTP X-windchill-req header. It supports various commands, including stealing Windchill secrets and configuration, mapping file vaults, enumerating directories and retrieving files, reading files, deleting files, loading and executing additional Java code, and identifying system information.

As more organizations become aware of this threat, it’s essential to remember that PTC began releasing fixes for CVE-2026-12569 on June 17. CISA has also added the vulnerability to its Known Exploited Vulnerabilities catalog following warnings of heightened threat activity. In light of these findings, it’s crucial for IT administrators to prioritize patching their Windchill servers and implementing robust security measures to prevent such attacks from succeeding in the future.


Source: Bleeping Computer — 2026-08-18