Clop created custom web shell for Windchill data theft attacks
Summary
The Clop ransomware gang has developed a custom Java web shell tailored for attacks against PTC Windchill and FlexPLM servers. This sophisticated tool includes functionalities for decrypting credentials, locating files, and exfiltrating data, indicating a targeted approach to exploiting these specific platforms.
IFF Assessment
This article details the development of a new, sophisticated tool by a known ransomware group, representing an increased threat to potential victims.
Defender Context
Defenders should be aware of this targeted approach against Windchill and FlexPLM systems, which could lead to significant data theft. Organizations using these platforms should ensure they are patched and monitored for unusual activity, especially credential harvesting and unauthorized file access.