View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Clop ransomware exploits PTC Windchill and FlexPLM in data theft

🚨 ACTIVE EXPLOITATION

  • Clop ransomware exploits PTC Windchill and FlexPLM in data theft attacks — BleepingComputer
    Clop ransomware gang is exploiting vulnerabilities in PTC Windchill and FlexPLM to steal data.
    • Targets PTC Windchill and FlexPLM Product Lifecycle Management (PLM) platforms used by engineering and manufacturing sectors
    • Exploits critical unsafe deserialization vulnerability CVE-2026-12569 allowing unauthenticated remote code execution
    • Deploys JSP webshells for remote command execution and exfiltration of sensitive product data
    • Extortion emails sent from support@cryptohox.com linked to Clop gang's new campaign
    • PTC released patches starting June 17, 2026; CISA and German BSI issued urgent warnings and mitigation orders

🕵️ RESEARCH & DEEP DIVES

  • UAC-0099 group uses fake Notepad++ plugin to deliver MATCHBOIL.V2 malware — The Hacker News
    UAC-0099 threat actors deploy MATCHBOIL.V2 malware via a fake Notepad++ plugin.

    • Targets Windows users via a fake Notepad++ plugin bundled with legitimate Notepad++ 8.8.3
    • Delivered through phishing emails with image attachments linking to a ZIP archive containing VBScript
    • VBScript downloads a decoy PDF and silently extracts malicious payloads including a DLL plugin and WinRAR executable
    • Malicious DLL (LUNCHPOKE) unpacks and runs BURNYBEAR loader and MATCHBOIL.V2 payload with persistence via scheduled tasks
    • Campaign attributed to Russia-aligned UAC-0099 group active since mid-2022, previously using WinRAR exploits and phishing
  • Western agencies warn of Russian hacks targeting Zimbra email servers since 2025 — Risky.Biz
    Western cyber agencies warn of ongoing Russian hacking campaign targeting Zimbra servers.

    • Targets: Zimbra email servers used by organizations with sensitive data and compliance needs
    • Vulnerability: Stored XSS zero-day (CVE-2025-66376) exploited via CSS @import in webmail client
    • Attack method: Malicious code loads Ulej tool to harvest credentials, tokens, 2FA codes, emails
    • Attribution: Linked to Russian APT group Laundry Bear (Void Blizzard, TA488) with Ukrainian targeting
    • Context: Part of broader Russian espionage on lesser-known email servers since 2022 invasion

🔓 CVEs & KEV

  • 18 CVEs reported with the highest severity at 7.3, details not specified in this update.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check