View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Cl0p Affiliates Exploit PTC Windchill and FlexPLM for Unauthenticated

🚨 ACTIVE EXPLOITATION

  • Cl0p Affiliates Exploit PTC Windchill and FlexPLM for Unauthenticated RCE Attacks — thehackernews.com
    Cl0p-linked threat actors are exploiting vulnerabilities in PTC Windchill and FlexPLM to achieve unauthenticated remote code execution, targeting manufacturing, automotive, aerospace, and retail sectors.
    • Targets internet-exposed PTC Windchill and FlexPLM deployments in manufacturing, automotive, aerospace, and retail sectors
    • Exploits a pre-authentication information disclosure in FlexPLM WSDL endpoint chained with a server-side flaw in Windchill login servlet
    • Enables unauthenticated remote code execution and deployment of JSP web shells under /Windchill/login/
    • Suspected exploitation of CVE-2026-12569 (CVSS 9.3) in Windchill and a FlexPLM WSDL endpoint flaw (CVSS 7.5)
    • Indicators of compromise include IPs: 216.152.148.54, 216.152.151.204, 104.243.35.63, 5.180.41.35

🕵️ RESEARCH & DEEP DIVES

  • DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Payouts — thehackernews.com
    DevMan ransomware operators run a centralized portal for payload creation, victim management, and affiliate payouts, targeting sectors including tech, healthcare, finance, and government.

    • Portal enables payload building, victim chat, finance tracking, team management, and affiliate payouts
    • Uses ChaCha20-Poly1305 encryption with multi-threaded file encryption targeting Windows, ESXi, and Linux systems
    • Affiliates operate under strict governance with curated victim assignments and an 80-20 revenue split
    • Developed a specialized SCADA locker to cause physical damage in industrial control systems
  • CTM360 uncovers real-time account hijacking in insurance phishing campaigns — thehackernews.com
    Insurance phishing campaigns now hijack accounts in real time during victim login sessions by relaying credentials and OTPs instantly.

    • Targets insurance customers using online portals for policies, claims, and payments
    • Attackers use Google Ads to lure victims to realistic phishing sites mimicking insurers
    • New InsureOTP phishing kit enables session management, live OTP handling, and attacker dashboards
    • Campaigns reuse infrastructure across Saudi Arabia, Europe, US, and India

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check