Lead story
Cl0p Has a New Trick: Chaining Two PLM Bugs to Extort Manufacturers Without Ransomware
The Cl0p crew — variously tracked as FIN11, Lace Tempest, and Graceful Spider — isn't content to keep repeating the MOVEit playbook. According to fresh reporting, affiliates linked to the group are now targeting internet-exposed deployments of PTC Windchill and FlexPLM, a pair of product lifecycle management platforms used heavily by manufacturers, defence contractors, and consumer goods companies worldwide.
The attack chain is elegant in a deeply annoying way. Attackers first hit a pre-authentication information-disclosure flaw in FlexPLM's WSDL endpoint — essentially a configuration file that leaks more than it should. They feed what they learn into a second vulnerability in the Windchill login servlet, which then lets them execute code on the server without ever providing valid credentials. No phishing. No brute-forcing. Just two bugs strung together into one quiet, automatic entry point.
What makes this especially notable is the pivot away from ransomware toward pure data extortion. Cl0p isn't encrypting files and demanding a decryption key — it's exfiltrating engineering data, supply-chain records, and design files, then threatening to publish them. This is the same model the group used after the MOVEit and GoAnywhere campaigns, and it works precisely because PLM systems sit at the heart of a manufacturer's crown jewels. The stolen data is often far more sensitive — and far harder to replace — than whatever a ransomware payment might recover.
Security researchers note that both Windchill and FlexPLM are commonly exposed to the internet for supplier and partner access, which is exactly the attack surface Cl0p is exploiting. That exposure is a feature for operations teams and a gift for threat actors.
Why it matters beyond the immediate victims. PTC's platforms are deployed across aerospace, automotive, industrial equipment, and defence manufacturing. Any organisation in those sectors running an unpatched, internet-facing deployment should treat this as a five-alarm situation. Shodan-style discovery of exposed instances is trivially easy for a well-resourced affiliate network.
For Australian readers, this warrants particular attention. Australia's defence industry supply chain — including tier-2 and tier-3 contractors supporting the AUKUS submarine programme, major infrastructure projects, and defence platform upgrades — relies heavily on PLM software from exactly this class of vendor. The SOCI Act's supply-chain risk obligations mean that any Australian critical infrastructure entity with an affected supplier should be checking whether those suppliers run exposed Windchill or FlexPLM instances, not just their own internal deployments. The ASD's Essential Eight wouldn't directly block the initial vector here, but patching and network segmentation of externally-facing PLM systems would.
What to watch. Cl0p has a well-documented pattern: discover a zero-day (or near-zero-day) in a widely-deployed file-transfer or collaboration platform, quietly exploit it at scale, then surface the victim list weeks later. The victims here may not know they've been hit yet. Expect a public extortion roster to emerge in the coming weeks.
In the meantime, if your organisation — or a supplier — runs either platform, the immediate action is straightforward: take the instance off the public internet if you can, apply available patches, and start reviewing outbound data transfer logs for anything anomalous.
