hacker-news · Crawled Jul 25, 2026

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

4 IoCs 3 Actors 1 Malware
Read original article ↗

AI Summary

Cl0p-affiliated threat actors are exploiting critical vulnerabilities in internet-exposed PTC Windchill and FlexPLM systems to achieve unauthenticated remote code execution. The attackers deploy hex-named JSP web shells to gain persistent access, conduct data exfiltration, and carry out double extortion. This campaign targets high-value sectors such as manufacturing, automotive, aerospace, and retail, leveraging known vulnerabilities to compromise enterprise applications.

AI-extracted · verify before operational use

Extracted Entities 4 found

Indicators of Compromise 4 extracted

Type Value Detail
IP 216[.]152[.]148[.]54 Details →
IP 216[.]152[.]151[.]204 Details →
IP 104[.]243[.]35[.]63 Details →
IP 5[.]180[.]41[.]35 Details →

MITRE ATT&CK TTPs 3 techniques