SUBJECT PROFILE
Cl0p affiliates are actively exploiting CVE-2026-12569 (CVSS 9.8), a critical unauthenticated RCE deserialization flaw in PTC Windchill and FlexPLM PLM platforms used by 30,000+ organizations globally. Suspected zero-day exploitation began in early June 2026 — five weeks before disclosure — with Ransom-ISAC, eCrime.ch, and DEFUSED publishing a coordinated advisory on July 25, 2026 confirming the attack chain. The campaign mirrors Cl0p's playbook from MOVEit and GoAnywhere: mass silent exploitation followed by bulk extortion emails sent to hundreds of users inside victim organizations.
Mass-exploitation data extortion; targets enterprise software supply chains for maximum victim breadth
OPERATIONAL HISTORY
Pre-auth information disclosure chaining (FlexPLM WSDL endpoint + Windchill login servlet), unauthenticated RCE via unsafe deserialization (CVE-2026-12569), hex-named JSP webshell deployment under /Windchill/login/, filesystem enumeration via flst.txt, engineering/design data staging, double-extortion via bulk organizational emails from compromised accounts
KNOWN INFRASTRUCTURE
Extortion emails sent from previously compromised accounts to hundreds of intra-org users; JSP webshells on /Windchill/login/; four confirmed attacker IPs shared across Ransom-ISAC and PTC advisories (updated July 27, 2026); CISA KEV catalog entry added June 25, 2026