Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Threat actors linked to the Cl0p ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.
Intelligence analysis by Llama

Cl0p affiliates are targeting internet-exposed PTC Windchill and FlexPLM deployments with unauthenticated RCE, enabling data theft and extortion attacks. The campaign is suspected to be exploiting CVE-2026-12569, a critical security flaw in PTC Windmill.
Imagine you have a super powerful tool that can break into any computer system. That's basically what the Cl0p ransomware group is doing. They're using a special trick to get into systems that are connected to the internet, and then they're stealing important files and demanding money in exchange for not releasing them. It's like a digital robbery, and it's very bad news for anyone who has important files on their computer.
Analysis
A $60B Vote of Confidence in Cl0p's Tactics
The Cl0p campaign is a prime example of the evolving tactics of ransomware groups. By targeting internet-exposed PTC Windchill and FlexPLM deployments, Cl0p affiliates are able to gain an initial foothold and conduct file system enumeration, stage engineering/design data, and ultimately carry out double extortion data theft. This campaign is suspected to be exploiting CVE-2026-12569, a critical security flaw in PTC Windmill that was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog late last month.
Why Cursor?
The extortion emails appear to originate from previously compromised accounts and are sent to hundreds of users within an impacted organization, along with ways to contact the Cl0p ransomware crew. This tactic is a clear indication of the group's ability to adapt and evolve their tactics to evade detection. The use of previously compromised accounts to send extortion emails is a clever move, as it allows the attackers to blend in with legitimate traffic and avoid raising suspicions.
The Road Ahead
The Cl0p campaign is a significant threat to organizations with internet-exposed PTC Windchill and FlexPLM deployments. The use of unauthenticated RCE and data theft tactics highlights the importance of patching vulnerabilities and securing enterprise applications. Organizations must take immediate action to patch CVE-2026-12569 and ensure that their PTC Windchill and FlexPLM deployments are secure. Additionally, organizations should implement robust security measures, such as multi-factor authentication and regular security audits, to prevent similar attacks in the future.
Key points
- Cl0p affiliates are targeting internet-exposed PTC Windchill and FlexPLM deployments with unauthenticated RCE.
- The campaign is suspected to be exploiting CVE-2026-12569, a critical security flaw in PTC Windmill.
- The extortion emails appear to originate from previously compromised accounts and are sent to hundreds of users within an impacted organization.
- The Cl0p campaign is a significant threat to organizations with internet-exposed PTC Windchill and FlexPLM deployments.
If the Cl0p campaign is stopped, it could lead to a decrease in ransomware attacks and a reduction in the financial burden on organizations. Additionally, the patching of CVE-2026-12569 could prevent similar attacks in the future.
If the Cl0p campaign is not stopped, it could lead to a significant increase in ransomware attacks and a substantial financial burden on organizations. Additionally, the continued exploitation of CVE-2026-12569 could result in widespread data theft and extortion.



