Clop-linked Windchill Web Shell Steals Credentials and Maps Engineering Data

Summary
ReliaQuest analyzes a custom web shell highly likely linked to Clop, deployed after exploitation of the Windchill CVE-2026-12569 flaw. The implant can decrypt stored credentials, map files for theft, and run additional code in memory.
Key points
- ReliaQuest links the custom web shell with high likelihood to Clop and exploitation of CVE-2026-12569, a CVSS 9.3 remote code execution flaw in PTC Windchill.
- The shell can decrypt credentials stored in Windchill’s keystore, including LDAP and administrator credentials, and enumerate vault files to identify sensitive engineering data.
- A custom Java class loader runs attacker-supplied code in memory, enabling potential follow-on activity such as lateral movement, persistence, malware deployment, or ransomware.
- The implant uses Windchill’s own application and database interfaces, a custom HTTP header, and GZIP-compressed responses to make activity harder to distinguish from normal traffic.
- ReliaQuest cites extortion emails, the shell’s custom header, and Clop’s established exploitation tradecraft as attribution evidence.
- Organizations should apply the vendor fix, hunt Windchill codebase directories for suspicious JSP files, and rotate all keystore credentials and any reused downstream credentials on suspected compromised systems.
- The article reports that CISA added CVE-2026-12569 to its Known Exploited Vulnerabilities catalog and required federal agencies to patch within three days.
Article Details
- Attack Vectors
- ReliaQuest assesses that Clop highly likely exploits CVE-2026-12569, a remote code execution flaw in PTC Windchill, to deploy a custom JSP web shell.
- The web shell's S command decrypts credentials from the Windchill keystore, including LDAP manager and administrative credentials; a separate command can exfiltrate the results.
- The implant queries Windchill's database to inventory vault files and writes their metadata to flst.txt to help select files for theft.
- A custom Java class loader accepts a Base64-encoded ZIP of compiled Java bytecode and executes it in memory. The article describes lateral movement, persistence, and ransomware as possible follow-on uses, not confirmed outcomes.
- Commands use the X-windchill-req HTTP header, and responses are GZIP-compressed.
- Defensive Notes
- Immediately apply the vendor fix for CVE-2026-12569 to all Windchill instances; restrict internet exposure of management interfaces, use a web application firewall, and monitor vulnerable endpoints.
- Inspect windchill/codebase/login and other Windchill codebase paths for unexpected JSP files, particularly files referencing X-windchill-req, MethodContext, WTConnection, or WTKeyStoreUtil.
- On suspected or confirmed compromised servers, rotate the LDAP manager password and all other credentials stored in the Windchill keystore, including credentials reused on downstream systems.
- Correlate web, application, database, file, and identity telemetry. Header logging, response decompression, and TLS inspection are needed for fuller visibility into the described web-shell traffic.
- Block identified attacker infrastructure, terminate sessions associated with exposed accounts, and disable affected accounts; IP blocking alone does not remove the web shell or invalidate stolen credentials.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 104[.]194[.]9[.]14 | IP address listed as associated with CVE-2026-12569 exploitation. |
| IPV4 | 104[.]243[.]35[.]63 | IP address listed as associated with CVE-2026-12569 exploitation. |
| IPV4 | 185[.]227[.]83[.]236 | IP address listed as associated with CVE-2026-12569 exploitation. |
| IPV4 | 209[.]222[.]98[.]44 | IP address listed as associated with CVE-2026-12569 exploitation. |
| IPV4 | 216[.]152[.]151[.]204 | IP address listed as associated with CVE-2026-12569 exploitation. |
| IPV4 | 5[.]180[.]41[.]35 | IP address listed as associated with CVE-2026-12569 exploitation. |
| IPV4 | 78[.]128[.]113[.]10 | IP address listed as associated with CVE-2026-12569 exploitation. |
| SHA256 | 321e1fb01eb3462b48ff6ccdef132acc1182e3f7456548439f0d4ead12fd98bf | Hash identified as Clop's custom web shell. |
MITRE ATT&CK
T1005 · Data from Local SystemThe deployed web shell has an arbitrary-file-read function for accessing data on the Windchill server.T1041 · Exfiltration Over C2 ChannelA separate web-shell command can exfiltrate credentials recovered by the S command.T1071.001 · Web ProtocolsThe web shell receives commands through the custom X-windchill-req HTTP header and returns GZIP-compressed responses.T1083 · File and Directory DiscoveryThe web shell queries vault file IDs, filenames, storage paths, and sizes and records the results in flst.txt.T1190 · Exploit Public-Facing ApplicationThe custom web shell is deployed after exploitation of the remote code execution flaw CVE-2026-12569 in PTC Windchill.T1505.003 · Web ShellThe attacker deploys a custom JSP web shell in the Windchill application to access credentials, files, and follow-on code execution.T1555 · Credentials from Password StoresThe web shell decrypts credentials held in the Windchill keystore, including the LDAP manager password and administrative credentials.T1620 · Reflective Code LoadingThe custom Java class loader loads compiled bytecode from an attacker-supplied Base64-encoded ZIP directly into memory and executes it without writing the added code to disk.
CVE
CVE-2021-27101previously deployed the custom web shell "DEWMODE" after exploiting the SQL injection vulnerability CVE-2021-27101, and it deployed "LEMURLOOT" after exploiting CVE-2023-34362.CVE-2023-34362the SQL injection vulnerability CVE-2021-27101, and it deployed "LEMURLOOT" after exploiting CVE-2023-34362.CVE-2026-12569“Clop's” exploitation of CVE-2026-12569 in PTC Windchill has returned the group to mass exploitation, delivering a custom web shell that provides full data-theft capability from the moment of deployment, with no
People
Threat Actors
Malware
China Chopperfunctions or simply offer a command prompt that allows threat actors to run their own instructions. "China Chopper," one of the most widely reused web shells in the threat landscape, illustrates the baseline: itsDEWMODEby custom-built web shell deployment. For example, Clop previously deployed the custom web shell "DEWMODE" after exploiting the SQL injection vulnerability CVE-2021-27101, and it deployed "LEMURLOOT" afterLEMURLOOTweb shell "DEWMODE" after exploiting the SQL injection vulnerability CVE-2021-27101, and it deployed "LEMURLOOT" after exploiting CVE-2023-34362.
Vendors
PTC“Clop's” exploitation of CVE-2026-12569 in PTC Windchill has returned the group to mass exploitation, delivering a custom web shell that provides full data-theft capability from the moment of deployment, with noReliaQuestThis is external threat intelligence from the ReliaQuest Threat Research team. The findings describe threats, vulnerabilities, and attacker activity affecting third parties and the broader threat landscape—not
Products
GreyMatterroutine. Detecting and containing it requires correlation across the full attack chain. ReliaQuest GreyMatter, an agentic AI security operations platform, provides capabilities directly relevant to the TTPsPTC Windchill“Clop's” exploitation of CVE-2026-12569 in PTC Windchill has returned the group to mass exploitation, delivering a custom web shell that provides full data-theft capability from the moment of deployment, with no