Threat Intelligence

Hackers Deploy Custom Web Shell to Steal Engineering Data via PTC Windchill Flaw

The Hacker News · 19 Aug 2026
Key Takeaway If your business uses specialised enterprise software like PLM systems, ensure patches and security updates are applied as soon as they are released to avoid becoming an easy target for data theft.

Security researchers at ReliaQuest have identified a sophisticated web shell being deployed against organisations using PTC Windchill and FlexPLM, enterprise software used to manage product lifecycle and engineering data. The malicious tool follows exploitation of a critical security flaw in these systems and is specifically built to target this type of enterprise software.

According to the findings, the web shell functions as a fully equipped extortion platform. It is capable of decrypting stored credentials and mapping out sensitive vault data, information that could include valuable intellectual property, engineering designs, and product specifications. The attack has been linked to the Clop ransomware group, known for large-scale data theft and extortion campaigns targeting vulnerable enterprise software.

While PTC Windchill and FlexPLM are typically used by larger manufacturing and engineering firms, this incident is a reminder that specialised business software can be a prime target for attackers seeking valuable data. Small and medium businesses that rely on any third-party enterprise software, particularly systems storing sensitive design or product data, should stay alert to vendor security advisories and apply patches promptly.

Windchill Clop ransomware web shell data extortion PLM security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.