<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Web-Shell on CuraSec</title><link>https://curasec.metacog.co.kr/tags/web-shell/</link><description>Recent content in Web-Shell on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 19 Aug 2026 11:36:35 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/web-shell/index.xml" rel="self" type="application/rss+xml"/><item><title>Clop custom Java web shell targets PTC Windchill and FlexPLM servers</title><link>https://curasec.metacog.co.kr/insights/2026-08-19-clop-created-custom-web-shell-for-windchill-data-theft-attac/</link><pubDate>Wed, 19 Aug 2026 11:36:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-19-clop-created-custom-web-shell-for-windchill-data-theft-attac/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> If you run PTC Windchill or FlexPLM, audit those servers for this Java web shell immediately — it is purpose-built to decrypt stored credentials and exfiltrate file repositories. Pull IOCs from the BleepingComputer article and sweep web-accessible directories on those hosts.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Clop&amp;rsquo;s use of a bespoke web shell against Windchill/FlexPLM indicates an active, ongoing campaign with credential theft as a precursor step; hunt for anomalous Java process activity and unauthorized file enumeration on any PLM servers in your estate, and ingest the published IOCs into your SIEM.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Clop is expanding its toolset to target PLM systems common in manufacturing and engineering sectors — verify whether Windchill or FlexPLM appears in your environment or third-party supply chain, and direct your security team to audit those systems this quarter.&lt;/li>
&lt;/ul></description></item><item><title>Clop-Linked JSP Web Shell Targets PTC Windchill/FlexPLM for Extortion</title><link>https://curasec.metacog.co.kr/insights/2026-08-19-clop-linked-windchill-web-shell-decrypts-credentials-and-map/</link><pubDate>Wed, 19 Aug 2026 11:36:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-19-clop-linked-windchill-web-shell-decrypts-credentials-and-map/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Clop-linked actors are actively exploiting a critical flaw in PTC Windchill and FlexPLM to deploy a purpose-built JSP web shell; if you run either platform, immediately audit PLM servers for rogue JSP files and apply the underlying critical patch.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active Clop-linked intrusion campaign targeting PLM servers with a web shell that harvests and decrypts credentials and maps vault contents — hunt for anomalous JSP execution and credential-access activity on Windchill/FlexPLM hosts, and review ReliaQuest&amp;rsquo;s analysis for behavioral indicators.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A Clop-affiliated extortion tool specifically engineered to steal engineering IP from PLM systems is a sector-specific risk for manufacturing, aerospace, and defense organizations; if Windchill or FlexPLM is in your environment or your supply chain, verify exposure and confirm vendor incident posture this quarter.&lt;/li>
&lt;/ul></description></item></channel></rss>