<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Clop on CuraSec</title><link>https://curasec.metacog.co.kr/tags/clop/</link><description>Recent content in Clop on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 19 Aug 2026 11:36:35 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/clop/index.xml" rel="self" type="application/rss+xml"/><item><title>Clop custom Java web shell targets PTC Windchill and FlexPLM servers</title><link>https://curasec.metacog.co.kr/insights/2026-08-19-clop-created-custom-web-shell-for-windchill-data-theft-attac/</link><pubDate>Wed, 19 Aug 2026 11:36:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-19-clop-created-custom-web-shell-for-windchill-data-theft-attac/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> If you run PTC Windchill or FlexPLM, audit those servers for this Java web shell immediately — it is purpose-built to decrypt stored credentials and exfiltrate file repositories. Pull IOCs from the BleepingComputer article and sweep web-accessible directories on those hosts.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Clop&amp;rsquo;s use of a bespoke web shell against Windchill/FlexPLM indicates an active, ongoing campaign with credential theft as a precursor step; hunt for anomalous Java process activity and unauthorized file enumeration on any PLM servers in your estate, and ingest the published IOCs into your SIEM.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Clop is expanding its toolset to target PLM systems common in manufacturing and engineering sectors — verify whether Windchill or FlexPLM appears in your environment or third-party supply chain, and direct your security team to audit those systems this quarter.&lt;/li>
&lt;/ul></description></item><item><title>Shell investigates Clop ransomware data theft claim (89GB)</title><link>https://curasec.metacog.co.kr/insights/2026-08-15-shell-investigates-potential-incident-after-clop-data-theft/</link><pubDate>Sat, 15 Aug 2026 11:32:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-15-shell-investigates-potential-incident-after-clop-data-theft/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Clop continues targeting large enterprises via data theft extortion; no IOCs or TTPs published yet — monitor for technical follow-up reports to inform detection tuning against Clop&amp;rsquo;s known access patterns.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> If Shell is a vendor or partner, request their incident status and any attestation of scope this week; even without confirmed breach, brief leadership before this surfaces in board or customer questions.&lt;/li>
&lt;/ul></description></item></channel></rss>