AI Security AI安全 10h ago Updated 2h ago 更新于 2小时前 48

Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE Cl0p附属组织针对互联网暴露的PTC Windchill和FlexPLM发起未授权远程代码执行攻击

Cl0p affiliates are exploiting unauthenticated vulnerabilities in PTC Windchill (CVE-2026-12569) and FlexPLM to achieve remote code execution. Attackers chain a pre-authentication information disclosure in FlexPLM with a server-side flaw in Windchill to deploy hex-named JSP web shells. The campaign targets high-value engineering and design data in manufacturing, automotive, aerospace, and retail sectors for double extortion. CVE-2026-12569 has been added to CISA’s Known Exploited Vulnerabilities Cl0p勒索软件团伙正利用PTC Windchill和FlexPLM中的未授权远程代码执行漏洞发起新一轮数据勒索攻击。 攻击者通过组合FlexPLM的信息披露缺陷与Windchill的服务器端漏洞,实现无需认证即可部署JSP Webshell并执行远程命令。 核心漏洞CVE-2026-12569(CVSS 9.3)已被列入CISA已知被利用漏洞目录,主要影响制造、汽车、航空航天及零售行业。 攻击者在获取初始访问权限后,会枚举文件系统、窃取工程与设计数据,并通过双重勒索手段进行数据窃取和敲诈。

75
Hot 热度
65
Quality 质量
60
Impact 影响力

Analysis 深度分析

TL;DR

  • Cl0p affiliates are exploiting unauthenticated vulnerabilities in PTC Windchill (CVE-2026-12569) and FlexPLM to achieve remote code execution.
  • Attackers chain a pre-authentication information disclosure in FlexPLM with a server-side flaw in Windchill to deploy hex-named JSP web shells.
  • The campaign targets high-value engineering and design data in manufacturing, automotive, aerospace, and retail sectors for double extortion.
  • CVE-2026-12569 has been added to CISA’s Known Exploited Vulnerabilities catalog due to active exploitation in the wild.

Why It Matters

This incident highlights the critical risk of internet-exposed enterprise PLM (Product Lifecycle Management) systems, which often contain highly sensitive intellectual property. For AI and security practitioners, it underscores the importance of monitoring not just general IT infrastructure but also specialized industrial software for known exploited vulnerabilities (KEVs). Immediate patching or network segmentation is essential to prevent data theft and ransomware deployment.

Technical Details

  • Vulnerability Chain: Attackers exploit CVE-2026-12569 (CVSS 9.3) in PTC Windchill, chaining it with a pre-authentication information disclosure defect in the FlexPLM WSDL endpoint (CVSS 7.5).
  • Exploitation Method: The combination allows unauthenticated remote code execution (RCE), enabling the deployment of hex-named JSP web shells under /Windchill/login/.
  • Post-Exploitation Activities: Once inside, actors perform file system enumeration, stage engineering/design data, and conduct double extortion by stealing sensitive product data.
  • Indicators of Compromise (IoCs): Four IP addresses identified as compromised or used by attackers: 216.152.148.54, 216.152.151.204, 104.243.35.63, and 5.180.41.35.
  • Target Sectors: Manufacturing, automotive, aerospace, and retail industries are specifically targeted due to the value of their design data.

Industry Insight

  • Immediate Patching Required: Organizations using PTC Windchill and FlexPLM must apply vendor patches immediately, especially since the vulnerability is already on CISA's KEV list.
  • Network Segmentation: Internet-exposed enterprise applications should be strictly segmented from internal networks to limit lateral movement and data exfiltration capabilities.
  • Monitor for Web Shells: Security teams should actively scan for hex-named JSP files in common web directories, particularly under login servlet paths, as this is a signature tactic of the current Cl0p campaign.

TL;DR

  • Cl0p勒索软件团伙正利用PTC Windchill和FlexPLM中的未授权远程代码执行漏洞发起新一轮数据勒索攻击。
  • 攻击者通过组合FlexPLM的信息披露缺陷与Windchill的服务器端漏洞,实现无需认证即可部署JSP Webshell并执行远程命令。
  • 核心漏洞CVE-2026-12569(CVSS 9.3)已被列入CISA已知被利用漏洞目录,主要影响制造、汽车、航空航天及零售行业。
  • 攻击者在获取初始访问权限后,会枚举文件系统、窃取工程与设计数据,并通过双重勒索手段进行数据窃取和敲诈。

为什么值得看

这篇文章揭示了Cl0p团伙将攻击目标从传统文件传输工具转向企业PLM(产品生命周期管理)系统的最新趋势,凸显了关键工业软件供应链的安全风险。对于IT和安全从业者而言,理解这种利用未授权RCE进行数据外泄的攻击链,有助于及时修补PTC相关组件并加强对外暴露面的监控。

技术解析

  • 攻击链机制:攻击者首先利用FlexPLM WSDL端点的预认证信息泄露缺陷(CVSS 7.5),随后结合PTC Windchill登录Servlet中的服务器端缺陷,形成链条以实现未授权的远程代码执行(RCE)。
  • 漏洞详情:主要利用的漏洞为CVE-2026-12569,存在于PTC Windchill中,评分高达9.3。该漏洞允许攻击者部署名为hex的JSP Webshell至/Windchill/login/目录下,进而执行任意系统命令。
  • 实施细节:一旦获得立足点,攻击者会进行文件系统枚举,专门定位并打包工程和设计数据等敏感资产,最终通过被窃取的内部账户发送勒索邮件,联系Cl0p团队。
  • 指标情报:Ransom-ISAC与PTC共同发布了四个受感染的IP地址作为妥协指标(IoCs),包括216.152.148.54、216.152.151.204、104.243.35.63和5.180.41.35,供防御方进行威胁狩猎。

行业启示

  • 强化PLM系统防护:制造和工程类企业应立即审查其PTC Windchill和FlexPLM部署,确保应用已更新至修复版本,并严格限制这些系统在互联网上的暴露面。
  • 关注企业应用漏洞:Cl0p团伙持续针对高价值企业应用(如Oracle E-Business Suite、SolarWinds等)发起攻击,安全团队需建立针对关键业务软件的快速补丁管理和异常行为检测机制。
  • 双重勒索应对策略:鉴于攻击者侧重于窃取而非仅加密数据,企业应加强数据备份的隔离性,并制定针对数据泄露事件的应急响应计划,以降低勒索成功率。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全