42
57
57
60
57
57
57
UAT-10608: Inside a large-scale automated credential harvesting operation targeting web applications
60
57
57
57
57
57
42
57
57
57
57
57
57
57
42
57
57
57
42
57
60
60
57
42
60
57
42
57
42
47
Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data
ReliaQuest details a bespoke JSP web shell that Clop deploys on hacked PTC Windchill and FlexPLM servers after exploiting CVE-2026-12569.
ReliaQuest analyzed a custom Java web shell planted on vulnerable PTC Windchill and FlexPLM servers following exploitation of CVE-2026-12569 (CVSS 9.3). The implant decrypts Windchill keystore credentials including the LDAP manager password, enumerates the file vault for engineering data, and loads attacker-supplied Java classes in memory for post-exploitation. Commands let operators read and delete files, exfiltrate results, and deliver follow-on payloads such as ransomware. Ransom-ISAC, eCrime.ch and Defused previously attributed the campaign to the Clop data-theft extortion group.
76
42
42