Clop-Linked Web Shell Exploits PTC Windchill Flaw to Decrypt Credentials and Map Engineering Data
A JavaServer Pages web shell, attributed to the Clop ransomware group, has been deployed in the wild following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers. The shell functions as an extortion platform capable of mapping sensitive vault data and decrypting credentials. The vulnerability, tracked as CVE-2025-3866, affects enterprise Product Lifecycle Management environments. PTC and ReliaQuest have been referenced in connection with the flaw and its analysis, respectively. The full extent of victim impact and data exfiltration remains under investigation.
