ATLAS · LIVE
ATLAS INDEX
Δ 24H
ACTIVE SOURCES20
HOTSPOTS20
TIME23:07:55 UTC
← All briefs
CRITICALCyber IntelligenceSunday, July 26, 2026

Cl0p Ransomware Affiliates Exploit PTC Software Flaws in New Extortion Campaign

Threat actors chain unauthenticated vulnerabilities in Windchill and FlexPLM to compromise internet-exposed enterprise product lifecycle management systems.

Affiliates of the Cl0p ransomware operation are exploiting critical vulnerabilities in PTC Windchill and FlexPLM deployments to conduct data extortion attacks. The threat actors—tracked under multiple aliases including Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest—are targeting internet-exposed installations of the enterprise product lifecycle management platforms.

The attack chain combines a pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint with a server-side vulnerability in the Windchill login servlet. This combination enables remote code execution without authentication, allowing attackers to gain initial access to corporate networks hosting sensitive product design, engineering, and supply chain data.

PTC Windchill and FlexPLM are widely deployed in manufacturing, aerospace, automotive, and industrial sectors for managing product data and development workflows. Organizations using these platforms often store intellectual property, engineering specifications, and supplier information—high-value targets for extortion operations.

The rest of this brief is inside the platform

Continue reading. Free.

A free Atlas account unlocks the full briefing, the co-analyst, daily delivery to your inbox, and a sector-personalised feed.

Full brief
Implications, sources, methodology
Co-Analyst
Ask follow-ups on every brief
Sector feed
Briefs filtered to what matters to you
Implications
  • 01Manufacturing and aerospace firms face intellectual property theft and operational disruption
  • 02PTC Windchill and FlexPLM administrators must patch and remove internet exposure immediately
  • 03Supply chain partners may be compromised through shared product development environments
  • 04Cyber insurance claims likely to increase as Cl0p targets expand beyond file transfer tools
Source
The Hacker News
https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html
Brief is editorial commentary by Atlas Intelligence based on the cited public reporting. Atlas does not reproduce source text. Verify primary source before action.
#ransomware#cl0p#ptc windchill#remote code execution#data extortion#manufacturing
Related Briefs