Clop-linked Windchill Web Shell Steals Credentials and Maps Engineering Data

· Original article ↗

Summary

ReliaQuest analyzes a custom web shell highly likely linked to Clop, deployed after exploitation of the Windchill CVE-2026-12569 flaw. The implant can decrypt stored credentials, map files for theft, and run additional code in memory.

Key points

  • ReliaQuest links the custom web shell with high likelihood to Clop and exploitation of CVE-2026-12569, a CVSS 9.3 remote code execution flaw in PTC Windchill.
  • The shell can decrypt credentials stored in Windchill’s keystore, including LDAP and administrator credentials, and enumerate vault files to identify sensitive engineering data.
  • A custom Java class loader runs attacker-supplied code in memory, enabling potential follow-on activity such as lateral movement, persistence, malware deployment, or ransomware.
  • The implant uses Windchill’s own application and database interfaces, a custom HTTP header, and GZIP-compressed responses to make activity harder to distinguish from normal traffic.
  • ReliaQuest cites extortion emails, the shell’s custom header, and Clop’s established exploitation tradecraft as attribution evidence.
  • Organizations should apply the vendor fix, hunt Windchill codebase directories for suspicious JSP files, and rotate all keystore credentials and any reused downstream credentials on suspected compromised systems.
  • The article reports that CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog and required federal agencies to patch within three days.

Article Details

Attack Vectors
  • ReliaQuest assesses that Clop highly likely exploits CVE-2026-12569, a remote code execution flaw in PTC Windchill, to deploy a custom JSP web shell.
  • The web shell's S command decrypts credentials from the Windchill keystore, including LDAP manager and administrative credentials; a separate command can exfiltrate the results.
  • The implant queries Windchill's database to inventory vault files and writes their metadata to flst.txt to help select files for theft.
  • A custom Java class loader accepts a Base64-encoded ZIP of compiled Java bytecode and executes it in memory. The article describes lateral movement, persistence, and ransomware as possible follow-on uses, not confirmed outcomes.
  • Commands use the X-windchill-req HTTP header, and responses are GZIP-compressed.
Defensive Notes
  • Immediately apply the vendor fix for CVE-2026-12569 to all Windchill instances; restrict internet exposure of management interfaces, use a web application firewall, and monitor vulnerable endpoints.
  • Inspect windchill/codebase/login and other Windchill codebase paths for unexpected JSP files, particularly files referencing X-windchill-req, MethodContext, WTConnection, or WTKeyStoreUtil.
  • On suspected or confirmed compromised servers, rotate the LDAP manager password and all other credentials stored in the Windchill keystore, including credentials reused on downstream systems.
  • Correlate web, application, database, file, and identity telemetry. Header logging, response decompression, and TLS inspection are needed for fuller visibility into the described web-shell traffic.
  • Block identified attacker infrastructure, terminate sessions associated with exposed accounts, and disable affected accounts; IP blocking alone does not remove the web shell or invalidate stolen credentials.

Indicators of compromise

TypeIndicatorContext
IPV4104[.]194[.]9[.]14IP address listed as associated with CVE-2026-12569 exploitation.
IPV4104[.]243[.]35[.]63IP address listed as associated with CVE-2026-12569 exploitation.
IPV4185[.]227[.]83[.]236IP address listed as associated with CVE-2026-12569 exploitation.
IPV4209[.]222[.]98[.]44IP address listed as associated with CVE-2026-12569 exploitation.
IPV4216[.]152[.]151[.]204IP address listed as associated with CVE-2026-12569 exploitation.
IPV45[.]180[.]41[.]35IP address listed as associated with CVE-2026-12569 exploitation.
IPV478[.]128[.]113[.]10IP address listed as associated with CVE-2026-12569 exploitation.
SHA256321e1fb01eb3462b48ff6ccdef132acc1182e3f7456548439f0d4ead12fd98bfHash identified as Clop's custom web shell.

MITRE ATT&CK

CVE

People

Threat Actors

Malware

Vendors

Products

Industries

Related Articles