The Clop threat group has returned to mass exploitation tactics by leveraging CVE-2026-12569 in PTC Windchill, deploying a sophisticated custom web shell designed specifically for data theft and extortion. This purpose-built implant provides immediate full data-theft capability without requiring additional tooling, featuring built-in credential harvesting, database enumeration, and a custom Java class loader for executing arbitrary code in memory. The web shell decrypts credentials from Windchill's keystore, including LDAP manager passwords that could enable enterprise-wide compromise. Its application-specific design allows malicious activity to blend seamlessly with legitimate traffic, making detection significantly more challenging. The implant targets sensitive intellectual property and engineering data stored in Windchill installations across manufacturing enterprises globally.
Created: 2026-08-19
Indicatorsは見つかっていない。
類似するPulseは見つかりませんでした。
事実ベースの脅威アクターは見つかりませんでした。
推論ベースの脅威アクターは見つかりませんでした。
このPulseに見つかったCVEはありません。