Clop Web Shell Decrypts Windchill LDAP, Admin Credentials

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- ReliaQuest identified a bespoke JSP web shell deployed after exploitation of CVE-2026-12569 (CVSS 9.3) in PTC Windchill and FlexPLM servers, calling it a fully equipped extortion platform tailored to the enterprise PLM software.
- Clop (Cl0p) was attributed by Ransom-ISAC, eCrime.ch, and Defused for the malicious activity that drops JSP web shells on susceptible systems, with 'Clop' references embedded throughout the implant per researchers.
- The web shell's single 'S' command returns Windchill's directory-management and administrative credentials in plaintext, including decryption of the LDAP manager password from the application keystore.
- Compromised LDAP credentials can govern access to Active Directory, email systems, and VPN, turning a single Windchill compromise into an enterprise-wide credential compromise per ReliaQuest.
- The implant uses Windchill's existing database identity rather than creating an attacker-controlled account and blends in with regular Windchill traffic to evade signature-based defenses.
- Clop previously deployed custom web shells DEWMODE and LEMURLOOT after exploiting SQL injection flaws in Accellion (CVE-2021-27101) and MOVEit Transfer (CVE-2023-34362), respectively, showing a pattern of bespoke tools for mass-exploitation campaigns.
- The web shell can run attacker-supplied code in memory via a Base64-encoded ZIP of compiled Java bytecode, enabling secondary payloads for persistence, lateral movement, or encryption on demand.
Why it matters: Windchill and FlexPLM store proprietary engineering data and product designs, and a single compromised instance can yield LDAP credentials that govern Active Directory, email, and VPN access. ReliaQuest frames this as a bespoke evolution of Clop's mass-exploitation playbook, meaning organizations running vulnerable Windchill instances face credential theft that operates inside the application's own trust boundary and mimics standard functions.
Ask SkimNews




