DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:09:16ZSOURCES: 14CRITICAL: 39
⚠ ACTIVE ALERTS
@MsftSecIntel CRITICAL — Microsoft Defender Experts tracked increased ACR Stealer activity from late April through… /// @TalosSecurity CRITICAL — Qilin RaaS remains the most active ransomware operation globally in 2026 with 500+… /// @CrowdStrike CRITICAL — VECT ransomware + TeamPCP supply chain credential theft + BreachForums mass affiliate… /// @MandiantThreats CRITICAL — Tracking Qilin affiliate recruitment activity on Russian-language cybercrime forums… /// @FalconFeedsio CRITICAL — Dark web monitoring alert: FIFA World Cup 2026 credential ecosystem fully operational on…
39Critical Threats
18Active CVEs
8IOCs Tracked
11New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // CLOP-WINDCHILL-2026FIRST SEEN: FEB 2019

CL0P

ALSO KNOWN AS: Chubby Scorpius, FIN11, Graceful Spider, Lace Tempest, TA505
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Russia/Eastern Europe (financially motivated)
ATTRIBUTION:ORGANIZED CRIME
STATUS:ACTIVE
FIRST OBSERVED:FEB 2019
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL82/100
RESOURCES82/100
PERSISTENCE85/100
STEALTH77/100
IMPACT91/100

Cl0p affiliates are actively exploiting CVE-2026-12569 (CVSS 9.8), a critical unauthenticated RCE deserialization flaw in PTC Windchill and FlexPLM PLM platforms used by 30,000+ organizations globally. Suspected zero-day exploitation began in early June 2026 — five weeks before disclosure — with Ransom-ISAC, eCrime.ch, and DEFUSED publishing a coordinated advisory on July 25, 2026 confirming the attack chain. The campaign mirrors Cl0p's playbook from MOVEit and GoAnywhere: mass silent exploitation followed by bulk extortion emails sent to hundreds of users inside victim organizations.

Mass-exploitation data extortion; targets enterprise software supply chains for maximum victim breadth

Pre-auth information disclosure chaining (FlexPLM WSDL endpoint + Windchill login servlet), unauthenticated RCE via unsafe deserialization (CVE-2026-12569), hex-named JSP webshell deployment under /Windchill/login/, filesystem enumeration via flst.txt, engineering/design data staging, double-extortion via bulk organizational emails from compromised accounts

MANUFACTURING
AUTOMOTIVE
AEROSPACE
RETAIL
PRODUCT LIFECYCLE MANAGEMENT

Extortion emails sent from previously compromised accounts to hundreds of intra-org users; JSP webshells on /Windchill/login/; four confirmed attacker IPs shared across Ransom-ISAC and PTC advisories (updated July 27, 2026); CISA KEV catalog entry added June 25, 2026

FILE DATE: JUN 2026
Windchill Zero-Day Pre-Patch Exploitation
Cl0p affiliates suspected of exploiting CVE-2026-12569 as a zero-day beginning early June, deploying JSP webshells and exfiltrating engineering/design IP from manufacturing and aerospace targets before PTC patch release.
FILE DATE: JUL 2026
Operation Windchill Extortion Wave
Ransom-ISAC confirmed July 20+ extortion campaign: bulk emails with subject 'Windchill ██████████████████████ data leak' sent to hundreds of users inside victim orgs across manufacturing, automotive, and aerospace sectors.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn