INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Clop Linked Windchill Web Shell Decrypts
| 2026-08-19 05:39 CRITICAL MEDIUMExecutive Summary AI-generated
The latest incident data reveals a sophisticated web shell deployed by threat actors, specifically those associated with the Clop ransomware operation. This bespoke web shell is tailored to exploit software vulnerabilities and provides a fully equipped extortion platform capable of mapping sensitive data, decrypting credentials, and running additional code. The web shell's custom Java class loader enables remote access and post-exploitation activity, including lateral movement, ransomware, and persistence. ReliaQuest attributes this malicious activity to Clop, with the threat actor dropping JSP web shells against susceptible systems. This indicates a high level of sophistication in the attack, as it leverages specific vulnerabilities (CVE-2026-12569) and exploits them to gain privileged access. The resulting web shell supports various commands, including S for returning Windchill credentials in plaintext, E for directly returning parameter values, and O for returning operating system names. This allows attackers to extract sensitive data and persist on compromised systems.
Technical Mitigations AI-generated
I can provide the following technical mitigations:
* Implement a secure coding practice to prevent similar vulnerabilities in future software development, such as:
+ Using input validation and sanitization techniques to prevent arbitrary code execution.
+ Avoiding the use of built-in functions that could be exploited by attackers (e.g., `gs` function mentioned in the article).
+ Ensuring that all API calls are properly validated and sanitized before being executed.
* Regularly update and patch software applications, including Windchill and FlexPLM servers, to ensure that known vulnerabilities are addressed.
* Use a web application firewall (WAF) or intrusion detection system (IDS) to detect and prevent attacks on the server-side.
* Implement secure authentication and authorization mechanisms to restrict access to sensitive data and systems.
* Conduct regular security audits and penetration testing to identify potential vulnerabilities and weaknesses in the software applications.
* Educate users about the risks of using web shells and other remote access tools, and provide guidance on how to securely use them.
Technical Observables
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
China ChopperChina Chopper
CVE-2026-12569CVE-2026-12569
CVE-2021-27101CVE-2021-27101
CVE-2023-34362CVE-2023-34362
Target & Sectors
CN
Incident Timeline
June 17
Threat actors exploited CVE-2026-12569 vulnerabilities in PTC's software to gain unauthorized access and map engineering data.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-12569
PTC began releasing fixes for CVE-2026-12569 on June 17, and
CISA later added
the vulnerability to its Known Exploited Vulnerabilities catalog following warnings of heightened threat activity.
attribution
PTC
PTC began releasing fixes for CVE-2026-12569 on June 17, and
CISA later added
the vulnerability to its Known Exploited Vulnerabilities catalog following warnings of heightened threat activity.
attribution
Known Exploited
PTC began releasing fixes for CVE-2026-12569 on June 17, and
CISA later added
the vulnerability to its Known Exploited Vulnerabilities catalog following warnings of heightened threat activity.
tactic
T1588.006 - Vulnerabilities
PTC began releasing fixes for CVE-2026-12569 on June 17, and
CISA later added
the vulnerability to its Known Exploited Vulnerabilities catalog following warnings of heightened threat activity.
2026/07/20
Threat actors used Clop ransomware to create and deploy JSP web shells against susceptible systems.
Click on any entity below to view its context and source!
tactic
Ransomware
An advisory
released
by Ransom-ISAC along with eCrime.ch and Defused last month attributed the malicious activity to the Clop (aka Cl0p) ransomware operation, with the threat actor dropping JSP web shells against susceptible systems.
organisation
Defused
An advisory
released
by Ransom-ISAC along with eCrime.ch and Defused last month attributed the malicious activity to the Clop (aka Cl0p) ransomware operation, with the threat actor dropping JSP web shells against susceptible systems.
2026/08/19
Clop created a custom web shell for PTC Windchill and FlexPLM servers.
Click on any entity below to view its context and source!
organisation
Windchill
The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault data, decrypting every credential in the Windchill keystore, and running additional code by means of a custom Java class loader, turning the tool into a backdoor for remote access and post-exploitation activity, such as lateral movement, ransomware, or persistence.
Clop created custom web shell for Windchill data theft attacks.
organisation
MFT
The Clop extortion gang has a long history of breaching enterprise platforms in data theft attacks, with previous campaigns targeting
Accellion FTA
,
GoAnywhere MFT
,
SolarWinds Serv-U FTP
,
Cleo
, and
MOVEit Transfer
file-sharing servers, the latter affecting
more than 2,770 organizations worldwide
.
organisation
SolarWinds Serv-U FTP
The Clop extortion gang has a long history of breaching enterprise platforms in data theft attacks, with previous campaigns targeting
Accellion FTA
,
GoAnywhere MFT
,
SolarWinds Serv-U FTP
,
Cleo
, and
MOVEit Transfer
file-sharing servers, the latter affecting
more than 2,770 organizations worldwide
.
victims
2,770 organizations
The Clop extortion gang has a long history of breaching enterprise platforms in data theft attacks, with previous campaigns targeting
Accellion FTA
,
GoAnywhere MFT
,
SolarWinds Serv-U FTP
,
Cleo
, and
MOVEit Transfer
file-sharing servers, the latter affecting
more than 2,770 organizations worldwide
.
organisation
JSP
Clop targeted exposed PTC Windchill and FlexPLM servers
in a data theft extortion campaign involving exploitation of CVE-2026-12569 and the deployment of JSP web shells.
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to
new findings
from ReliaQuest.
organisation
PTC Windchill
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files.
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to
new findings
from ReliaQuest.
organisation
The Hacker News
"The web shell gives attackers a direct path to credential theft and large-scale data exfiltration, with no additional tooling required," ReliaQuest said in a report shared with The Hacker News.
organisation
Cybersecurity company ReliaQuest
Cybersecurity company ReliaQuest analyzed the web shell after it is believed to have been deployed in recent data theft attacks exploiting CVE-2026-12569, a critical remote code execution vulnerability affecting PTC Windchill.
organisation
CVE-2023-34362
The e-crime group was previously observed dropping
DEWMODE
and
LEMURLOOT
after exploiting SQL injection flaws in Accellion (
CVE-2021-27101
) and MOVEit Transfer (
CVE-2023-34362
) file transfer software, respectively.
organisation
SQL
The e-crime group was previously observed dropping
DEWMODE
and
LEMURLOOT
after exploiting SQL injection flaws in Accellion (
CVE-2021-27101
) and MOVEit Transfer (
CVE-2023-34362
) file transfer software, respectively.
organisation
Accellion
The e-crime group was previously observed dropping
DEWMODE
and
LEMURLOOT
after exploiting SQL injection flaws in Accellion (
CVE-2021-27101
) and MOVEit Transfer (
CVE-2023-34362
) file transfer software, respectively.
organisation
Maps Engineering Data
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data.
organisation
Product Lifecycle Management
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to
new findings
from ReliaQuest.
organisation
PLM
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to
new findings
from ReliaQuest.
organisation
ReliaQuest
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to
new findings
from ReliaQuest.
ReliaQuest says the implant is not a generic web shell repurposed for the attacks, but was instead built with detailed knowledge of Windchill's internal APIs, database schema, keystore, and file-vault structure.
organisation
BleepingComputer
"This appears to be an application-specific evolution of Clop's established mass-exploitation playbook," ReliaQuest said in a report shared with BleepingComputer.
organisation
Windchill
Analysis
A web shell built specifically for Windchill
Analysis by ReliaQuest and BleepingComputer confirms the tool was designed to target Windchill servers rather than act as a generic web shell.
organisation
MethodContext
The malware is a JavaServer Pages (JSP) web shell that directly imports Windchill-specific classes, including MethodContext, WTConnection, and WTKeyStoreUtil.
organisation
Commands
Commands supported by the Clop Windchill web shell
Source: BleepingComputer
The web shell supports the following commands:
S
– Steal Windchill secrets and configuration:
Reads Windchill's LDAP configuration and uses the application's own
WTKeyStoreUtil.decryptProperty()
function to decrypt the LDAP manager password and other encrypted application data.
organisation
J
– Load
J
– Load and execute additional Java code:
Passes a Base64-encoded ZIP archive and loads compiled Java bytecode directly into memory and executes it within the Windchill process.
organisation
ApplicationData
BleepingComputer's analysis shows that these tables are ApplicationData, FVITEM, FVMOUNT, and MasteredOnReplicaItem.
organisation
FVITEM
BleepingComputer's analysis shows that these tables are ApplicationData, FVITEM, FVMOUNT, and MasteredOnReplicaItem.
organisation
FVMOUNT
BleepingComputer's analysis shows that these tables are ApplicationData, FVITEM, FVMOUNT, and MasteredOnReplicaItem.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Tactical Metrics
Metrics
victims
2,770
Organizations
Click for context!
The Clop extortion gang has a long history of breaching enterprise platforms in data theft attacks, with previous campaigns targeting
Accellion FTA
,
GoAnywhere MFT
,
SolarWinds Serv-U FTP
,
Cleo
, and
MOVEit Transfer
file-sharing servers, the latter affecting
more than 2,770 organizations worldwide
.
Intelligence Sources
BleepingComputer
2026-08-18
Clop created custom web shell for Windchill data theft attacks
BleepingComputer
The Hacker News
2026-08-19
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-20T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
25x
organisation
Identified Entity
Windchill
entity
6x
tactic
Cyber Operation Type
Extortion
tactic
3x
vulnerability
Exploited CVE
CVE-2026-12569
cve
3x
tactic
MITRE ATT&CK Technique
T1505.003 - Web Shell
technique
2x
timeline
Temporal Reference
2026/07/20
date
2x
attribution
Attributing Entity
PTC
authority
Contextual Telemetry
Context Block
7 METRICS
target region
Target Country
China
country
malware
Malware Payload
China Chopper
tool
general metric
Web Shell
9
web shell
victims
Organizations
2,770
organizations
general metric
Cve-2026
12,569
cve-2026
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.