CYBERSECURITYTRACKER
TRACKING6,528 stories in this site build1,321 vulnerability news stories in this site build
Permanent story citation

Clop created custom web shell for Windchill data theft attacks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4615

As cited

Copy frozen at (site build).

ransomware

Clop created custom web shell for Windchill data theft attacks

A custom Java web shell attributed to the Clop ransomware gang was engineered for PTC Windchill and FlexPLM servers, featuring credential decryption, repository enumeration, and file theft capabilities. The tool reflects the group's targeted approach to compromise product lifecycle management platforms.

Why it matters: Organizations running Windchill or FlexPLM need to audit access logs, detect web shell artifacts, and ensure these systems are isolated or heavily monitored, as they often store sensitive product designs and intellectual property.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Clop created custom web shell for Windchill data theft attacks

A custom Java web shell attributed to the Clop ransomware gang was engineered for PTC Windchill and FlexPLM servers, featuring credential decryption, repository enumeration, and file theft capabilities. The tool reflects the group's targeted approach to compromise product lifecycle management platforms.

Why it matters: Organizations running Windchill or FlexPLM need to audit access logs, detect web shell artifacts, and ensure these systems are isolated or heavily monitored, as they often store sensitive product designs and intellectual property.

VendorsOracle
Actorsclop
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary