Cl0p Ransomware Affiliates Exploit PTC Software Flaws in New Extortion Campaign
Threat actors chain unauthenticated vulnerabilities in Windchill and FlexPLM to compromise internet-exposed enterprise product lifecycle management systems.
Affiliates of the Cl0p ransomware operation are exploiting critical vulnerabilities in PTC Windchill and FlexPLM deployments to conduct data extortion attacks. The threat actors—tracked under multiple aliases including Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest—are targeting internet-exposed installations of the enterprise product lifecycle management platforms.
The attack chain combines a pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint with a server-side vulnerability in the Windchill login servlet. This combination enables remote code execution without authentication, allowing attackers to gain initial access to corporate networks hosting sensitive product design, engineering, and supply chain data.
PTC Windchill and FlexPLM are widely deployed in manufacturing, aerospace, automotive, and industrial sectors for managing product data and development workflows. Organizations using these platforms often store intellectual property, engineering specifications, and supplier information—high-value targets for extortion operations.
- 01Manufacturing and aerospace firms face intellectual property theft and operational disruption
- 02PTC Windchill and FlexPLM administrators must patch and remove internet exposure immediately
- 03Supply chain partners may be compromised through shared product development environments
- 04Cyber insurance claims likely to increase as Cl0p targets expand beyond file transfer tools
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.