The long tail of Clopβs PTC hack is just beginning to emerge
A notorious cybercrime group has once again exploited a critical zero-day vulnerability on a large scale, claiming it stole data from dozens of organizations, including some of the worldβs largest publicly traded companies.
Clop, a prolific but calculated data theft extortion group thatβs been active since 2020, began sending threatening emails to its alleged victims in mid-July, according to researchers.Β
The fallout from the attack spree, which followed a familiar pattern for Clop and its targeted pool of victims, is still evolving as companies hunt for potential signs of compromise.
The vulnerability at the center of Clopβs latest campaign affects a pair of software products from PTC β Windchill and FlexPLM β which manufacturers and retailers, particularly in the manufacturing, aerospace, and automotive industries, use to automate supply chain systems and manage product lifecycles.
βThis continues Clopβs trend of targeting SaaS logistics companiesβ platforms with zero-days and carrying out mass-exploitation campaigns,β Allan Liska, field chief information security officer at Recorded Future, told CyberScoop.
PTC disclosed the vulnerability β CVE-2026-12569 β on June 17 and issued a patch and initial indicators of compromise the following day.Β
Yet, that was too late for some of Clopβs known victims who were likely compromised by exploitation of the zero-day in early June, according to Ransom-ISAC.
The Cybersecurity and Infrastructure Security Agency added the defect, which allows unauthenticated attackers to execute code remotely, to its known exploited vulnerabilities catalog June 25.
PTC consistently added new indicators of compromise as they were discovered by researchers. But the company hasnβt said how it first became aware of the vulnerability and ensuing attacks, when the earliest known instance of exploitation occurred or how many customers are known to be compromised.Β
PTC did not respond to a request for comment.Β
Clopβs claimed victim set is diverse. The point-of-sale restaurant management platform Toast and software vendor Zebra both told CyberScoop they detected and contained system intrusions, but claimed limited impacts. Other alleged victims, including GE, Philips and Shell, did not respond to requests for comment.Β
Researchers continue to uncover new details about the tools Clop used once it exploited and gained access to PTC customer systems. ReliaQuest said the group used a custom web shell that gave attackers a direct path to credential theft and large-scale data theft.
The fully equipped extortion platform, which was purpose-built for Windchill, decrypts credentials, delivers malware, and includes tools for sustained access, network traversal and data encryption, ReliaQuest researchers wrote in a report Tuesday.
The toolkit allows attackers to move quickly from initial access to data theft and additional post-exploitation activity without executing manual commands β a framework that mimics Windchillβs standard functions and limits defendersβ ability to detect any malicious activity.
βThis campaign is another reminder that Clop remains a sleeping dragon, always looking and preparing to mass exploit vulnerabilities in software that holds sensitive data,β ReliaQuest researchers wrote in the report. βThe group commonly goes inactive between campaigns but springs to life with custom-built web shells whenever there is another opportunity for mass extortion.βΒ
The drawn-out impact of Clopβs latest attack spree also mirrors some of its previous campaigns. The threat group has successfully exploited zero-days across multiple technology vendorsβ systems, allowing it to steal sensitive data for weeks β sometimes months β from many downstream customers.
Clop targeted dozens of Oracle E-Business Suite customers for more than three months, beginning in the summer of 2025, before it started bombarding victims with extortion emails. The group also achieved mass exploitation as it infiltrated MOVEit environments in 2023, ultimately exposing data from more than 2,300 organizations, making it the largest and most significant cyberattack that year.
The post The long tail of Clopβs PTC hack is just beginning to emerge appeared first on CyberScoop.