# PTC Windchill and FlexPLM Targeted in Clop Data Theft Campaign

> Clop ransomware targets PTC Windchill and FlexPLM systems. Learn about the CVE-2022-25247 exploit risks and how to secure exposed PLM instances from extortion.

- Published: 2026-07-24T10:20:39.000Z
- Severity: high
- Category: Threat Intel
- Tags: Clop, PTC Windchill, FlexPLM, CVE-2022-25247, Ransomware
- Author: Runtime Rebel Intel
- Primary source: https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/
- Canonical: https://runtimerebel.com/blog/ptc-windchill-and-flexplm-targeted-in-clop-data-theft-campaign

## Key points

- Immediate impact: Clop is exfiltrating sensitive intellectual property from PTC Windchill and FlexPLM instances to conduct high-pressure extortion attacks.
- Affected systems: Internet-exposed versions of PTC Windchill and PTC FlexPLM, specifically those vulnerable to authentication bypass flaws.
- Remediation: Organizations must apply PTC security patches and remove PLM management interfaces from the public internet immediately.

The Clop ransomware group (also tracked as Cl0p) has demonstrated a consistent [TTP](/glossary#ttp) of identifying and exploiting vulnerabilities in enterprise-grade file transfer and management software. Their latest campaign, according to [BleepingComputer](https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/), indicates a shift toward Product Lifecycle Management (PLM) platforms. By targeting internet-exposed PTC Windchill and FlexPLM instances, the group aims to conduct large-scale **Clop ransomware data theft extortion** operations. Unlike traditional [Ransomware](/glossary#ransomware) attacks that focus on file encryption, Clop’s current strategy prioritizes the exfiltration of sensitive proprietary data, which provides greater leverage during the extortion phase.

## Technical Analysis of Clop Data Exfiltration TTPs

PTC Windchill is a widely used PLM solution that manages sensitive product data, blueprints, and supply chain workflows, while FlexPLM is specifically tailored for retail and consumer products. These systems often hold the "crown jewels" of an organization's intellectual property. Clop has historically succeeded by automating the discovery of [CVE](/glossary#cve) vulnerabilities in niche but high-value software, as seen in their previous [Supply Chain Attack](/glossary#supply-chain-attack) campaigns involving MOVEit and Accellion. 

### Exploitation of [CVE-2022-25247](https://nvd.nist.gov/vuln/detail/CVE-2022-25247)

A primary vector of concern in this campaign involves the exploitation of an authentication bypass. The vulnerability at the center of many of these discussions is CVE-2022-25247, which carries a [CVSS](/glossary#cvss) score of 9.8. This critical flaw allows for remote authentication bypass, potentially granting an attacker administrative access to the platform without valid credentials. Understanding the **PTC Windchill CVE-2022-25247 exploit** path is essential for [SOC](/glossary#soc) teams, as it involves the manipulation of web-tier components to gain unauthorized entry. Once access is achieved, Clop actors utilize [C2](/glossary#c2) infrastructure to stage exfiltration tools, allowing them to siphon terabytes of data before the organization is even aware of the breach.

Analysts should monitor for [IoC](/glossary#ioc) sets associated with known Clop activity, including unusual outbound traffic to suspicious IP ranges and the presence of unauthorized administrative accounts. The group frequently uses [Lateral Movement](/glossary#lateral-movement) techniques to identify additional data repositories once the initial PLM instance is compromised. Implementing [EDR](/glossary#edr) tools can help detect the post-exploitation activity that typically follows the initial [Ransomware](/glossary#ransomware) group's entry. The use of [MITRE ATT&CK](/glossary#mitre-att-ck) framework mapping, specifically technique T1190 (Exploit Public-Facing Application), can assist in developing detection logic within a [SIEM](/glossary#siem).

## How to Secure PTC FlexPLM Instances

Defenders must prioritize the reduction of their attack surface by ensuring these platforms are not directly accessible from the public internet. When researching **how to secure PTC FlexPLM instances**, administrators should first verify their current patch level against PTC's official security advisories. If a system must be internet-facing, it should be protected by a [Zero Trust](/glossary#zero-trust) architecture or at minimum a strictly controlled VPN. 

1. **Verify Exposure:** Use scanning tools to identify any PTC Windchill or FlexPLM management interfaces visible to the public web.
2. **Patch Immediately:** Ensure all security updates for PTC products are applied, specifically focusing on those that resolve authentication bypass and remote code execution vulnerabilities.
3. **Enhanced Logging:** Enable verbose logging for web server components and monitor for unexpected HTTP status codes or unusual URI patterns that may indicate exploit attempts.
4. **Credential Audit:** Review all administrative accounts within the PLM environment and enforce multi-factor authentication (MFA) across the board.

**Related:** [CVE-2022-25247: PTC Windchill RCE Exploited in the Wild](/blog/cve-2022-25247-ptc-windchill-rce-exploited-in-the-wild), [Accenture Confirms Breach: LockBit 2.0 Ransomware and Stolen Data](/blog/accenture-confirms-breach-lockbit-2-0-ransomware-and-stolen-data)

---

AI-generated analysis from the primary source above; not human-reviewed before publication — verify anything operational against the original (https://runtimerebel.com/editorial). Quote with attribution and a link to the canonical URL: https://runtimerebel.com/blog/ptc-windchill-and-flexplm-targeted-in-clop-data-theft-campaign
