CuraSec

tag: Clop-Ransomware · 2 items

2026-08-19 · The Hacker News · source ↗ #web-shell#clop-ransomware#plm-security
  • Engineer — Act: Clop-linked actors are actively exploiting a critical flaw in PTC Windchill and FlexPLM to deploy a purpose-built JSP web shell; if you run either platform, immediately audit PLM servers for rogue JSP files and apply the underlying critical patch.
  • SOC/IR — Act: Active Clop-linked intrusion campaign targeting PLM servers with a web shell that harvests and decrypts credentials and maps vault contents — hunt for anomalous JSP execution and credential-access activity on Windchill/FlexPLM hosts, and review ReliaQuest’s analysis for behavioral indicators.
  • Leader — Plan: A Clop-affiliated extortion tool specifically engineered to steal engineering IP from PLM systems is a sector-specific risk for manufacturing, aerospace, and defense organizations; if Windchill or FlexPLM is in your environment or your supply chain, verify exposure and confirm vendor incident posture this quarter.
2026-07-24 · BleepingComputer · source ↗ #clop-ransomware#plm-software#data-theft
  • Engineer — Act: Clop is actively targeting internet-exposed PTC Windchill and FlexPLM instances — both are common in manufacturing, aerospace, and retail/apparel supply chains. Immediately audit whether any Windchill or FlexPLM deployments are internet-reachable and restrict or take them offline; review recent access logs for anomalous data staging or egress activity.
  • SOC/IR — Act: Clop’s pattern of mass data theft before extortion demands a proactive hunt in any organization running these PLM products — look for large exfiltration events from Windchill or FlexPLM hosts in your SIEM and baseline normal egress volumes now. Pull the BleepingComputer article for any published IOCs or TTPs and build detection coverage against Clop’s known staging and exfil behaviors in EDR telemetry.
  • Leader — Act: Clop has a documented track record of bulk data theft followed by public dumps, which can trigger SEC disclosure obligations and customer notification requirements. If your organization is in manufacturing, automotive, aerospace, or retail/apparel, confirm this week whether Windchill or FlexPLM is in the environment and request an exposure assessment from engineering before Clop publishes any victim list.