Clop created custom web shell for Windchill data theft attacks

A custom web shell, built specifically for PTC Windchill servers, has been discovered in recent data theft attacks linked to the notorious Clop ransomware gang. The web shell’s advanced features allow it to decrypt credentials, enumerate file repositories, and steal files with ease, making it a formidable tool in the hands of cyber attackers.

The web shell, which was analyzed by cybersecurity company ReliaQuest, is believed to have been deployed in attacks exploiting CVE-2026-12569, a critical remote code execution vulnerability affecting PTC Windchill. This vulnerability was recently patched by PTC on June 17, but it’s clear that the Clop gang has been actively exploiting it for some time.

What sets this web shell apart from others is its level of sophistication and customization. It was built with intimate knowledge of Windchill’s internal APIs, database schema, keystore, and file-vault structure. This suggests a high degree of insider knowledge or extensive research on the part of the attackers. As ReliaQuest notes, “This appears to be an application-specific evolution of Clop’s established mass-exploitation playbook.”

The web shell is controlled using a custom protocol sent through the HTTP X-windchill-req header, which contains eight characters with specific commands embedded within. The supported commands include stealing Windchill secrets and configuration, mapping file vaults, enumerating directories and retrieving files, reading and deleting files, loading and executing additional Java code, and identifying files.

The Clop gang has a long history of breaching enterprise platforms in data theft attacks, targeting various secure file-sharing applications. This latest campaign is just the latest example of their relentless efforts to exploit vulnerabilities and steal sensitive data. The fact that they have created a custom web shell specifically for Windchill servers suggests a deep understanding of the application’s inner workings.

As organizations continue to grapple with the aftermath of these attacks, it’s essential to remember that prevention is key. Keeping software up-to-date, implementing robust security measures, and monitoring network activity are all crucial steps in preventing similar attacks from happening in the future.

In particular, Windchill administrators should be on high alert for potential threats, ensuring that their systems are patched and secure. It’s also essential to educate employees about the risks of data theft and the importance of reporting any suspicious activity. By staying vigilant and proactive, organizations can minimize the risk of falling victim to these types of attacks.

Ultimately, the discovery of this custom web shell serves as a stark reminder of the evolving nature of cyber threats. As attackers continue to adapt and innovate, it’s essential for security professionals to stay one step ahead. By working together and sharing knowledge, we can better protect our systems and prevent these devastating attacks from happening in the first place.


Source: Bleeping Computer — 2026-08-18