Executive Summary
- On June 17, 2026, product lifecycle management (PLM) and industrial/IoT software vendor PTC disclosed a critical remote code execution vulnerability in their PLM tool Windchill and add-on FlexPLM (CVE-2026-12569). On July 20, Ransom-ISAC reported that multiple organizations began receiving emails confirmed to be from the Cl0p ransom/extortion group, warning that their “confidential information” had been stolen.
- PTC’s customer base includes organizations across aerospace and defense, electronics, energy, industrial systems, and medical technology verticals, among others.
- This disclosure comes just three months after PTC disclosed an earlier critical RCE affecting the same products (CVE-2026-4681); there is no currently known exploitation of this earlier vulnerability.
- As far back as June 1, 2026, Censys observed fewer than 100 instances of PTC Windchill exposed to the Internet, with a decline in exposed instances shortly after PTC’s initial advisory publication on June 17, 2026.
- 80% of observed Windchill instances are found in the U.S., and nearly a quarter of hosts running Windchill are on Akamai infrastructure, which aligns with the product’s enterprise customer profile.
- To date, vendor PTC has published 12 IOC IP addresses associated with this campaign. During the suspected attack time frame of early to mid June, Censys observed rapid service churn–in some cases, up and down in less than 24 hours–across these IP addresses, pointing to the short-lived nature of attack infrastructure.
- Cl0p has new email contact information and infrastructure, powered by registrar CNOBIN, Cloudflare nameservers, and Roundcube Webmail on their own self-hosted mail server.
Introduction
On July 22, 2026, ReliaQuest reported observations of a threat actor exploiting CVE-2026-12569, a critical remote code execution (RCE, 9.8) vulnerability affecting product lifecycle management software PTC Windchill and FlexPLM. This CVE was disclosed on June 17, 2026, and according to the Ransom-ISAC, it’s likely that this vulnerability was exploited in early June 2026 as a zero-day. PTC began releasing patches for affected versions as early as June 18, and continued over the next several weeks.
The vulnerability was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on June 25, 2026. On the same day at 1pm ET, PTC posted updated IOCs and remediation steps in their advisory, stating, “Over the last several hours, we’ve received continued reports of heightened threat activity. We urge you to apply all patches and remediations immediately.”
Ransom-ISAC noted that beginning July 20, an unknown number of organizations began receiving emails with the subject, “Windchill PDMLink module serious data leak” that include Cl0p’s newest email addresses.

At the time of analysis, Cl0p’s leak site does not list any new data publications, simply an announcement confirming that the cryptohox[.]com and cypherhex[.]com addresses are their current contact information.

This attack comes on the heels of another critical RCE in PTC Windchill from March 2026 (CVE-2026-4681). There is currently no known or confirmed exploitation of CVE-2026-4681. On March 26, 2026, CISA released an ICS advisory for this vulnerability, given the adoption of Windchill across the critical manufacturing sector.
Campaign Context
PTC’s Windchill and FlexPLM are product lifecycle tools designed to aid in engineering and manufacturing processes. FlexPLM is an add-on for Windchill, designed specifically for retail, fashion, footwear, and apparel companies to manage their product development processes.
Exploitation of enterprise back office software via zero day exploit is a well-known Cl0p technique. MOVEit, GoAnywhere, OracleEBS, and numerous other attacks followed this pattern, but the type of data likely stolen in this campaign sets it apart from previous Cl0p activity. Rather than a company’s financials, HR and employee data, or customer details, data in the Windchill platform is likely more focused on engineering and manufacturing processes.
Data stolen from these instances may include files like product designs and specs, bills of materials, supplier and vendor data, and other intellectual property. This is particularly concerning given that PTC’s customer base includes defense contractors, energy suppliers, medical technology companies, and electronics manufacturers, among others.
Censys ARC Perspective
Exposed Windchill infrastructure

The graph above illustrates exposure of PTC Windchill instances, including those with the FlexPLM add-on, from early June through late July, 2026. The late June decline in exposures began several days after PTC’s initial advisory publication on June 17 as more details were made available. This may coincide with operators taking their instances offline to patch.
At time of analysis, roughly 80% of observed instances were found in the U.S., and based on hostname analysis, exposures fall across large brands and organizations in agricultural and industrial machinery, apparel, retail, and water and building infrastructure, among others.
Many exposures of enterprise software are concerning not only because of the type of data involved, but the quantity of exposed instances. During the 2023 Cl0p campaign against MOVEit Transfer, there were over 2,000 instances exposed to the Internet; during the 2025 Oracle E-Business Suite attacks, over 2,700 instances were online. With relatively few instances of PTC Windchill exposed to the Internet, this campaign serves as a reminder that an exposure does not have to be widespread or globally prominent to be a valuable target.

Nearly a quarter of the underlying hosts running Windchill are found on Akamai’s network, which aligns with the enterprise profile of this software. Apart from Windchill instances on CDN and cloud networks, several instances were found on ASes belonging to the user organizations themselves (not shown in the graph above).
Known IOC infrastructure
As of PTC’s advisory update on July 9, 2026 at 10:55 am ET, there were 12 IP addresses and one CIDR range (104.243.35.0/24) reportedly associated with this campaign. As of this analysis, none of the SSH keys that appeared on these individual IPs in early June are currently found on any other infrastructure.
The hosts are found on a variety of abuse-tolerant VPS and hosting providers in the U.S., Australia, Canada, Hong Kong, and others. Providers include Enzu Cloud (AS18978), GTHost (AS63023), ReliableSite (AS23470), InterServer (AS19318), CrownCloud, Miti 2000 EOOD (AS209160), and LightNode (AS154177).
Only one host, 5.180.41[.]35, was explicitly referenced as a C2 in PTC’s advisory with explicit instruction to “block at perimeter”. The other 11 hosts are listed as general IOCs, and customers are encouraged to scan their environments for signs of these indicators.

We visualize the SSH service churn across the 12 IOC IPs not to decisively determine any timelines of attack, but rather to illustrate the often rapid churn of infrastructure used in such attacks. SSH services appearing on 104.243.35.64:37866 and 216.152.151.204:16453 may indicate that a new operator occupies the host: there are new SSH key fingerprints for these services, there been a gap of multiple days between these services and the previous SSH services, and these are on high non-standard ports rather than standard port 22.
5.180.41[.]35 was the first confirmed C2 IP address reported in PTC’s advisory on June 18. While this host has no services currently visible to Censys, on June 11, we observed an SSH/22 service with a key distinct from the previous SSH/22 service come online and quickly disappear within less than 24 hours. This host is found on Enzu cloud, a U.S.-based IT infrastructure provider.
78.128.113[.]10 is anomalous when compared to the other hosts in the IOC list. A persistent SSH/22 service has been up since April 23, 2026, and as of July 17, the host presents an open directory on ports 9999 and 19999 containing Platypus C2 tooling. This is not a known Cl0p TTP and may be unrelated to the Windchill exploitation activity.
During June 2026, only two of the IOC hosts ran a service other than SSH:
38.60.157[.]212- HTTP/19999; Netdata monitoring dashboard; June 22–23
104.243.35[.]131- HTTP/80; Nginx with an HTTP response body of
{"status": "", "stages": "overview vmstress cpubench cputherm drvsmart drvbench wipedata"}which may be a custom hardware stress test system; June 4-5
- HTTP/80; Nginx with an HTTP response body of
New Email Domains
The Cl0p actors have also updated their contact information as of July 2026. Per their data leak site, their new email addresses are support[@]cypherhex.com and support[@]cryptohox[.]com.


Each of these domains were registered nearly simultaneously on July 17, 2026 via CNOBIN, a known bulletproof domain provider.

At the time of analysis, we observe that cryptohox[.]com has an A record pointing to 193.24.211[.]236, found on Data Campus Limited (AS215929) in Bulgaria, while cypherhex[.]com has an A record pointing to 200.107.207[.]15, found on DATAHOME S.A. (AS273045) in Russia. Both hosts use Cloudflare’s nameservers.

cryptohox[.]comThe hosts have similar profiles, both running a full stack mail server and hosting a login for Roundcube Webmail, each instance of which appears to be on the latest patch version (1.7.2). Both hosts also have a srv. subdomain, which is tied to an MX record for each host.
| Service | Port(s) | 200.107.207.15 | 193.24.211.236 |
|---|---|---|---|
| SMTP | 25, 465, 587 | Y | Y |
| HTTP | 80, 443 | Y | Y |
| POP3 | 110, 995 | Y | Y |
| NTP | 123 (udp) | Y | Y |
| IMAP | 143, 993 | Y | Y |
| MySQL | 3306 | Y | Y |
| SSH | 60193 | N | Y |
The only notable difference between the two hosts, apart from being on different networks, is the SSH service on 193.24.211[.]236:60193.
Without knowing these hosts are associated with Cl0p, they would appear entirely unremarkable, perhaps apart from the non-standard SSH service, though even that isn’t so unusual.
Conclusion
This activity is a reminder that Internet-exposed enterprise back office software remains a high value target for threat actors. While many previous Cl0p campaigns targeted software with broader exposure (MOVEit, over 2,000 instances; Oracle E-Business Suite, over 2,700 instances), this campaign illustrates that a smaller exposure footprint does not equate to lower risk. This is especially true when the organizations themselves–defense contractors, energy providers, and electronics manufacturers, for example–are high value targets.
Organizations running Windchill or FlexPLM are strongly encouraged to patch as soon as possible, given active exploitation since early June and remediation guidance available in PTC’s advisory. Beyond patching, organizations should also consider removing Windchill instances from the public Internet.
| IOC Host / Block | Censys Platform Link |
|---|---|
5.180.41.35 | https://platform.censys.io/hosts/5.180.41.35 |
38.60.157.212 | https://platform.censys.io/hosts/38.60.157.212 |
74.50.76.146 | https://platform.censys.io/hosts/74.50.76.146 |
78.128.113.10 | https://platform.censys.io/hosts/78.128.113.10 |
104.194.9.14 | https://platform.censys.io/hosts/104.194.9.14 |
104.243.35.63 | https://platform.censys.io/hosts/104.243.35.63 |
104.243.35.131 | https://platform.censys.io/hosts/104.243.35.131 |
172.111.38.31 | https://platform.censys.io/hosts/172.111.38.31 |
185.227.83.236 | https://platform.censys.io/hosts/185.227.83.236 |
209.222.98.44 | https://platform.censys.io/hosts/209.222.98.44 |
216.152.148.54 | https://platform.censys.io/hosts/216.152.148.54 |
216.152.151.204 | https://platform.censys.io/hosts/216.152.151.204 |
104.243.35.0/24 | https://platform.censys.io/search?q=host.ip%3A+%22104.243.35.0%2F24%22+ |

