Clop Gang Uses Custom Web Shell for Targeted Windchill Data Theft

The Clop ransomware group developed a custom Java web shell targeting PTC Windchill and FlexPLM servers, enabling credential decryption, file enumeration, and data theft.

Why it matters

This activity highlights the use of tailored malware to target critical enterprise software, underscoring the importance of recognizing advanced data theft tactics.

SOC impact

Monitor network and server logs associated with Windchill and FlexPLM deployments for unusual access or command activity indicating web shell presence. Investigate signs of credential decryption and unauthorized file enumeration to detect potential data theft attempts.

Recommended actions

  1. Identify deployed instances of Windchill and FlexPLM servers in the environment
  2. Review authentication and access logs for anomalous behavior linked to these applications
  3. Inspect files and processes for indicators of a custom Java web shell
  4. Monitor for signs of credential decryption or unusual file browsing activity
  5. Correlate security telemetry to detect data exfiltration attempts targeting enterprise assets

Executive Summary

The Clop ransomware group has developed a specialized Java web shell designed specifically to target PTC Windchill and FlexPLM servers. This custom malware enables attackers to decrypt credentials, enumerate files, and steal data, demonstrating a focused approach to compromising critical enterprise applications.

For defenders, this signifies increased risks related to enterprise software environments that manage product lifecycle and configuration data. Identifying and monitoring for this tailored tool is essential to detecting sophisticated data theft campaigns and containing associated threats.

SOC Impact

Monitor network and server logs associated with Windchill and FlexPLM deployments for unusual access or command activity indicating web shell presence. Investigate signs of credential decryption and unauthorized file enumeration to detect potential data theft attempts.

Detection and Monitoring of Web Shell Activity

  • Identify deployed instances of Windchill and FlexPLM servers in the environment
  • Review authentication and access logs for anomalous behavior linked to these applications
  • Inspect files and processes for indicators of a custom Java web shell
  • Monitor for signs of credential decryption or unusual file browsing activity
  • Correlate security telemetry to detect data exfiltration attempts targeting enterprise assets

Why It Matters

This activity highlights the use of tailored malware to target critical enterprise software, underscoring the importance of recognizing advanced data theft tactics.

Source