We Published the Exact Hunt Pattern on June 26. Clop Just Listed 43 Windchill Victims Including Shell, GE and Philips.
- Patrick Duggan
- 2 hours ago
- 5 min read
On August 17 the Clop extortion group listed 43 new victims on its leak site, all claimed via internet-exposed PTC Windchill and FlexPLM instances, exploiting CVE-2026-12569. Shell, General Electric and Philips are among the named. Clop's running total is now roughly 1,300 victims, 46 of them in the last thirty days.
We published the detection guidance for this on June 26 — the day CISA added the CVE to the Known Exploited Vulnerabilities catalog. Here is the line, verbatim:
"Search your web logs for any POST request to a path matching /Windchill/login/ followed by sixteen hex characters and .jsp."
And the companion:
"Scan for newly-created JSP files under the Windchill web root whose names are sixteen-character hex strings."
That is the receipt. Not a vibe, not a "we've been tracking this space" — a specific, falsifiable string pattern, published seven weeks before the mass-extortion wave that dropped exactly those files.
What I Am and Am Not Claiming
I want to be precise about this, because the easiest way to destroy a threat intel shop's credibility is to inflate a real win into a fake one.
I am not claiming we discovered CVE-2026-12569. PTC found and patched it. CISA listed it. We did not.
I am not claiming we predicted Clop specifically. Our June 26 post explicitly said the exploitation was already underway and not theoretical — German authorities were physically warning companies before the CISA listing, which told us there was real victim telemetry behind it. We documented an active campaign; we did not forecast an attribution.
What I am claiming is narrower and, I think, more useful: on the day this went on the KEV list, we published a concrete hunt pattern precise enough for a defender to grep for, and seven weeks later the largest mass-extortion campaign of the quarter is built on exactly that artifact. A defender who read that post in June and ran that query had a chance to find the webshell before the leak-site listing. That is what the work is for.
We also told people, in that same post, the thing most Windchill coverage still is not saying: "If you find one, assume the foothold predates the webshell. Deserialization RCE gives code execution first; the webshell is the persistence they install afterward." If you are only now hunting hex-named JSPs and you find one, your incident did not start today.
For the record, we also got this wrong once in public and corrected it. On July 25 we wrote that we had "no Windchill indicators in our corpus before this week." That was false — we had written the hunt guidance a month earlier and forgotten we had. We published the correction the next day. Institutional memory is only worth something if you actually check it, and we did not.
Why Clop Keeps Winning With the Same Play
Clop has run one playbook, without meaningful deviation, for years. MOVEit. GoAnywhere. Cleo. Oracle E-Business Suite. Now Windchill and FlexPLM.
The pattern:
Find one enterprise platform that sits on the internet. Not an endpoint, not a laptop — a server that an organization deliberately exposed because remote access to it was the point.
Pick one that holds everything. File transfer, ERP, product lifecycle. A single system where the crown jewels aggregate by design.
Pick one nobody thinks of as attack surface. This is the load-bearing step. Nobody's threat model has a box labeled "product lifecycle management." It is not on the security team's asset list because it belongs to engineering, and it is not on engineering's risk register because it is a business application.
Burn one bug in it. Then take the data from every exposed instance at once, before the patch cycle completes.
The genius is not technical. It is target selection. Clop understands better than most defenders which systems are simultaneously critical, exposed, and organizationally orphaned.
Why PLM Is the Worst Possible Version of This
Windchill and FlexPLM are where manufacturers keep how a physical product is designed and built. CAD models. Bills of materials. Test reports. Tolerances. Supplier specifications. Facility documentation. Manufacturing process instructions.
Think about what that means for the three named companies and the forty others.
A stolen customer database is a privacy incident with a defined remediation: notify, monitor, indemnify, absorb the fine. Painful, bounded, well-understood.
A stolen product design corpus is a permanent transfer of engineering advantage. You cannot rotate a bill of materials. You cannot re-issue a decade of test data. If a competitor or a state industrial program obtains the complete design record for a product line, that value does not expire, and there is no notification letter that fixes it.
For regulated manufacturers the problem compounds. In medical devices — which is why we flagged this angle back in July — the design history file is not just intellectual property, it is a regulatory artifact. Design inputs, verification and validation records, risk analysis, the whole 21 CFR 820.30 trail frequently lives in or alongside PLM. Exfiltrating it exposes device architecture and the safety reasoning behind it in one pull.
And unlike a MOVEit incident, where the stolen files are at least somebody else's data you were holding, this is the company's own capability walking out the door.
What to Do This Week
Assume compromise if you were exposed, do not assume patched means clean. The patch stops new exploitation. It does nothing about a webshell installed before you applied it. This is the single most common failure in mass-exploitation response and it is why Clop's victim counts keep climbing months after patches ship.
Run the hunt patterns. POST requests to /Windchill/login/ plus sixteen hex characters plus .jsp, in your web logs, going back to at least the disclosure date. New JSP files under the Windchill web root with sixteen-hex-character names, on disk, right now.
Then look earlier than the webshell. Deserialization RCE means code execution came first. The webshell is the persistence, not the entry.
Get PLM onto the asset inventory that security actually reads. If Windchill was not on your internet-exposed critical systems list before this week, the real finding is not the CVE. It is that you have a class of system nobody owns. Clop will pick the next one from that same class, and the only question is which vendor.
Check what else in that class you have exposed. Managed file transfer. ERP. PLM. Anything that aggregates and faces the internet by design. That is the entire target pool for the next campaign, and the list is not long.
The Honest Scorecard
We were early with a usable detection on this one and we can prove it with a dated, specific string. That is a genuine win and I will take it.
We also published a factually wrong sentence about our own coverage a month later and had to correct it in public. That is a genuine miss, and it happened because we did not search our own corpus before making a claim about our own corpus.
Both of those are the same story: the value here is not being clever once, it is checking. The hunt pattern was worth something because it was specific enough to be wrong. The correction was necessary because the claim was specific enough to be checked.
Forty-three companies are finding out this week what was in their PLM. Some of them could have looked in June.
Sources
CISO Platform, "Breach Watch, August 17, 2026: Clop Hits Shell, GE, Philips via PTC Windchill Flaw"
ReliaQuest, "Clop Returns with Custom Implant in Mass-Extortion Campaign"
CISA Known Exploited Vulnerabilities catalog, CVE-2026-12569, listed June 25, 2026
Our June 26 post, "The Manufacturing Brain Just Went on the KEV List," and the July 26 correction, "We Told You to Hunt Hex-Named JSP Files on June 26" — both at dugganusa.com
If you ran that hunt and found something, I want to know — both because it matters and because it is the only way we learn whether our detections are worth anything. Rate this post below.
Her name was Renee Nicole Good.
His name was Alex Jeffery Pretti.




Comments