CuraSec

tag: Web-Shell · 2 items

2026-08-19 · The Hacker News · source ↗ #web-shell#clop-ransomware#plm-security
  • Engineer — Act: Clop-linked actors are actively exploiting a critical flaw in PTC Windchill and FlexPLM to deploy a purpose-built JSP web shell; if you run either platform, immediately audit PLM servers for rogue JSP files and apply the underlying critical patch.
  • SOC/IR — Act: Active Clop-linked intrusion campaign targeting PLM servers with a web shell that harvests and decrypts credentials and maps vault contents — hunt for anomalous JSP execution and credential-access activity on Windchill/FlexPLM hosts, and review ReliaQuest’s analysis for behavioral indicators.
  • Leader — Plan: A Clop-affiliated extortion tool specifically engineered to steal engineering IP from PLM systems is a sector-specific risk for manufacturing, aerospace, and defense organizations; if Windchill or FlexPLM is in your environment or your supply chain, verify exposure and confirm vendor incident posture this quarter.
2026-08-19 · BleepingComputer · source ↗ #clop#web-shell#plm
  • Engineer — Act: If you run PTC Windchill or FlexPLM, audit those servers for this Java web shell immediately — it is purpose-built to decrypt stored credentials and exfiltrate file repositories. Pull IOCs from the BleepingComputer article and sweep web-accessible directories on those hosts.
  • SOC/IR — Act: Clop’s use of a bespoke web shell against Windchill/FlexPLM indicates an active, ongoing campaign with credential theft as a precursor step; hunt for anomalous Java process activity and unauthorized file enumeration on any PLM servers in your estate, and ingest the published IOCs into your SIEM.
  • Leader — Plan: Clop is expanding its toolset to target PLM systems common in manufacturing and engineering sectors — verify whether Windchill or FlexPLM appears in your environment or third-party supply chain, and direct your security team to audit those systems this quarter.