
Cl0p Ransomware Group Exploits Vulnerabilities in PTC Windchill and FlexPLM Systems
Threat actors affiliated with the Cl0p ransomware group (also known as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) are actively exploiting vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments as part of a data extortion campaign. The attack chain combines a pre-authentication information disclosure flaw in the FlexPLM WSDL endpoint with a server-side vulnerability in the Windchill login servlet, enabling unauthenticated remote code execution (RCE). No specific CVE identifiers, dates, or affected software versions were disclosed in the reported details. The campaign targets publicly accessible instances of these enterprise product lifecycle management (PLM) systems. The impact includes potential unauthorized access, data theft, and extortion through ransomware deployment.