Cl0p-linked threat actors are actively exploiting unauthenticated remote code execution vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments. The attackers chain a pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint with a server-side vulnerability in the Windchill login servlet to achieve code execution without requiring valid credentials.
PTC Windchill and FlexPLM are widely deployed product lifecycle management and collaboration platforms used by manufacturing, aerospace, automotive, and engineering firms to manage design data, product configurations, and supply chain information. Internet-facing instances of these systems are prime targets for data theft operations.
The Cl0p group, also tracked as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest, operates as a ransomware-as-a-service outfit focused on extortion. The group has previously exploited zero-day vulnerabilities in Ivanti, Progress Software, and Salesforce products to harvest sensitive intellectual property and customer data before deploying ransomware.
This campaign represents a shift in tactics. Rather than immediately encrypting systems, Cl0p affiliates are extracting proprietary designs, technical specifications, and business records from targeted organizations. The threat actors then demand ransom payments in exchange for non-disclosure of the stolen data.
Organizations running Windchill or FlexPLM should immediately verify whether instances are accessible from the internet and restrict network access to trusted locations only. PTC has released patches addressing these vulnerabilities. Organizations unable to patch immediately should implement web application firewall rules to block suspicious requests to the WSDL endpoint and login servlet.
The risk extends beyond the targeted organization. Supply chain partners, customers, and competitors may face exposure if sensitive product designs or roadmap information is leaked
