Clop exploits PTC zero-day in mass extortion

The long tail of Clop's PTC zero-day campaign is just beginning to emerge

The notorious Clop ransomware group has once again executed a mass-extortion campaign by exploiting a critical zero-day vulnerability -- this time in PTC's Windchill and FlexPLM software, which manufacturers and retailers use to automate supply chain systems and manage product lifecycles. The vulnerability, tracked as CVE-2026-12569, allows unauthenticated attackers to execute code remotely. PTC disclosed the flaw and issued a patch on June 17, but by then Clop had already compromised victims.

Clop began sending threatening extortion emails to alleged victims in mid-July. The claimed victim set is diverse and includes major publicly traded companies: GE, Philips, Shell, restaurant management platform Toast, and software vendor Zebra. Toast and Zebra confirmed system intrusions but reported limited impacts. The campaign follows Clop's established playbook of exploiting zero-days in enterprise software to steal sensitive data en masse from downstream customers -- a pattern seen in its 2023 MOVEit campaign (which ultimately affected over 2,300 organizations) and its 2025 Oracle E-Business Suite attacks.

Researchers at ReliaQuest revealed that Clop used a custom web shell purpose-built for Windchill that decrypts credentials, delivers malware, and includes tools for sustained access, network traversal, and data encryption. The toolkit allows attackers to move from initial access to data theft without executing manual commands, mimicking Windchill's standard functions to evade detection. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on June 25.

The drawn-out impact continues to evolve as companies hunt for signs of compromise. Clop has been active since 2020 and is known for going dormant between campaigns before springing to life with custom-built tools whenever a new mass-exploitation opportunity arises.

References