Clop builds custom web shell for PTC Windchill data theft
Source headline: Clop created custom web shell for Windchill data theft attacks
Intelligence Summary
Clop ransomware is linked to a custom Java web shell aimed at PTC Windchill and FlexPLM servers. The shell includes functions to decrypt credentials used in the environment. It can also enumerate file repositories to locate stored data. The payload is designed to steal files from those repositories. If you run PTC Windchill or FlexPLM, review for web shell activity and investigate for unauthorized access and data theft.
Recommended Action
Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.