Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Clop ransomware operators deployed a custom JSP web shell against PTC Windchill and FlexPLM servers after exploiting CVE-2026-12569, a critical improper input-validation flaw carrying a CVSS score of 9.3.
- ReliaQuest characterized the implant as a "fully equipped extortion platform" that decrypts every credential in the Windchill keystore, maps stored vault data, and uses a custom Java class loader to run additional code — all without external commands.
- A single "S" command reads Windchill's "ieStructProperties.txt" configuration file, decrypts the LDAP manager password from the application keystore, and iterates through stored local properties to expose administrative account credentials, object storage keys, and all site administrator values in plaintext.
- The web shell supports commands including file vault enumeration writing "flst.txt" (L), arbitrary file reads (G), file deletion (R), and Java class loading (J) from Base64-encoded ZIP files executed directly in memory.
- References to "Clop" throughout the implant align the activity with the gang's prior custom web shells DEWMODE (Accellion, CVE-2021-27101) and LEMURLOOT (MOVEit Transfer, CVE-2023-34362), per ReliaQuest researchers John Dilgen and Connor Short.
- The implant executes queries through Windchill's existing database identity rather than a new attacker-controlled account, blending with regular application traffic to limit signature-based detection according to ReliaQuest.
Why it matters: Because Windchill credentials govern LDAP access — and LDAP governs Active Directory, email, and VPN — a single PLM compromise can cascade into enterprise-wide credential theft, ReliaQuest warned. The 9.3 CVSS flaw paired with an implant that mimics native application behavior means defenders cannot rely on standard detection signals to catch the activity.
Ask SkimNews




