Cl0p Ransomware Affiliates Exploit Unauthenticated RCE in Internet-Facing PTC Windchill and FlexPLM Servers

Cl0p Ransomware Affiliates Exploit Unauthenticated RCE in Internet-Facing PTC Windchill and FlexPLM Servers

Cybercriminals associated with the Cl0p ransomware group are actively exploiting a critical remote code execution vulnerability in PTC Windchill and FlexPLM software, compromising exposed servers without needing any logi…

Security researchers are warning that affiliates of the notorious Cl0p ransomware operation are actively scanning the internet for vulnerable PTC Windchill and FlexPLM servers, exploiting a critical security flaw that allows attackers to execute malicious code remotely without any authentication. This type of attack, known as unauthenticated remote code execution (RCE), means that a vulnerable server can be fully taken over simply by sending a specially crafted request over the internet. No password or user account is needed, making it particularly dangerous for systems that are directly accessible from the public web.

PTC Windchill and FlexPLM are enterprise software products used for product lifecycle management (PLM), a process that helps organizations manage the entire lifecycle of a product from inception, through engineering design and manufacture, to service and disposal. These applications often contain sensitive intellectual property, design files, and operational data, making them high-value targets for ransomware groups. When an unauthenticated RCE flaw is present, attackers can install backdoors, steal data, or deploy ransomware payloads, effectively crippling an organization’s operations.

The Cl0p group, also tracked as TA505 or FIN11, is known for its long history of financially motivated cybercrime, including large-scale ransomware campaigns and data extortion. In this campaign, the affiliates appear to be focusing on internet-exposed instances of the vulnerable PTC software. Once a vulnerable server is identified, the attackers can exploit the flaw to gain initial access, then move laterally within the network, escalate privileges, and deploy the Cl0p ransomware. This approach mirrors previous Cl0p attacks that exploited zero-day vulnerabilities in managed file transfer solutions like Accellion FTA and Fortra GoAnywhere MFT, which led to widespread data breaches.

The immediate risk is for any organization that runs PTC Windchill or FlexPLM with a version that has not been patched against this specific RCE vulnerability. Because the attack requires no user interaction, even a server that is simply connected to the internet without proper network segmentation or firewall rules is at risk. Once compromised, attackers can exfiltrate confidential data and threaten to publish it unless a ransom is paid, a double-extortion tactic commonly used by Cl0p.

To defend against this threat, it is critical that administrators immediately identify all internet-facing PTC systems and apply the necessary software updates or workarounds provided by the vendor. If patches are not yet available, organizations should consider taking those systems offline or placing them behind a virtual private network (VPN) with strong authentication. Additionally, deploying a web application firewall (WAF) can help filter malicious traffic, and network monitoring tools can detect unusual activity that may indicate an attempted or successful compromise. For website owners and IT teams who rely on hosting providers, choosing a service that includes proactive security measures—such as AEU Hosting’s managed WordPress hosting with built-in firewalls and regular vulnerability scanning—can add an important layer of defense against remote exploits, even if the vulnerable software is not directly related to web hosting.

How to Protect Yourself

  1. Check with your IT team or software provider whether you use PTC Windchill or FlexPLM, and immediately install any available updates or patches for those programs.
  2. If you manage a server yourself, ensure it is not directly accessible from the public internet unless absolutely necessary; use a firewall to limit access to only trusted network addresses.
  3. Turn on automatic updates for all your software, including server applications, to ensure you receive security fixes as soon as they are released.
  4. Use a web application firewall (WAF) service that can filter out malicious traffic before it reaches your server.
  5. Make regular backups of your important data and store them offline or in a separate cloud service, so you can recover quickly if your system is compromised.
  6. If you are unsure how to secure your server, consider using a managed hosting provider that handles security patching and monitoring for you.

Related AEU services

  • AEU-I IT and security consulting