Published: · Region: Global · Category: cyber

Cl0p-Linked Hackers Exploit New Industrial RCE to Squeeze Manufacturers’ Engineering Data

Affiliates tied to the Cl0p ransomware group are actively exploiting a critical remote-code-execution flaw in internet-exposed PTC Windchill and FlexPLM systems, dropping webshells and stealing engineering data from manufacturing, automotive, aerospace, and retail firms. The campaign shows how industrial design files have become bargaining chips in global cyber extortion, with a separate DevMan ‘ransomware-as-a-service’ platform now offering affiliates a turnkey portal to scale similar attacks.

A ransomware crew linked to the Cl0p group is turning a newly exposed industrial software flaw into leverage over some of the world’s most design-sensitive sectors, exploiting a critical unauthenticated remote-code-execution vulnerability in PTC’s Windchill and FlexPLM systems to steal engineering data for double extortion. Security researchers report that the attackers are chaining two bugs to gain a foothold on internet-exposed servers, then planting distinctively named JSP webshells to maintain access.

Windchill and FlexPLM sit at the heart of product lifecycle management for manufacturing, automotive, aerospace, and major retail brands. They house CAD drawings, bill-of-materials data, and proprietary design details that can define a company’s competitive edge for years. By targeting these systems directly, the Cl0p-linked affiliates are bypassing the old model of encrypting random file servers and instead going straight for the crown jewels that executives are least willing to see leaked or destroyed.

For engineers and operations teams, the intrusion risk is not limited to stolen blueprints. Compromised PLM servers can ripple across development pipelines, triggering shutdowns of design environments, delays in prototyping, and urgent audits of which projects and partners share affected data. Companies with global supply chains must then confront whether compromised design files have already migrated to suppliers, subcontractors, or joint-venture partners in jurisdictions with weaker defenses or different regulatory expectations.

The campaign lands at the same time as another worrying development in the ransomware ecosystem: the rapid professionalization of “DevMan,” a ransomware-as-a-service (RaaS) platform that security specialists track under the codename Funky Mantis. Researchers say DevMan now runs a full affiliate portal, complete with payload builders, victim management, chat tools, team coordination, support functions, and automated payout handling. Affiliates reportedly receive structured workflows, deadlines, and an 80/20 revenue split, with the platform claiming 184 victims so far.

Together, the Cl0p-linked industrial exploits and the DevMan portal show how cyber extortion has shifted from improvised heists to an industrial model of its own. Instead of one monolithic gang, the threat is now an ecosystem in which specialists find vulnerabilities, others build exploits, and a rotating cast of affiliates execute campaigns against targets in multiple countries and sectors. For states already worried about intellectual property theft and supply chain espionage, the line between traditional cybercrime and strategic technology loss is becoming much harder to draw.

For policymakers and boards, the practical consequence is that design rooms and R&D centers are now national-security-relevant assets, even when they sit inside nominally private firms. When an aerospace supplier’s PLM server is compromised, the damage is not just to that company’s balance sheet; it can expose data on components that appear in military aircraft, satellite systems, or critical infrastructure. Ransom notes demanding cryptocurrency payments may be the most visible symptom, but the enduring harm lies in who else might quietly obtain and weaponize the stolen data.

Key signs to watch in the coming weeks will include vendor patches and advisories from PTC and major industrial suppliers, disclosure of breaches in regulatory filings, and any law-enforcement action linking DevMan or the Cl0p-linked affiliates to specific jurisdictions. If additional RaaS platforms adopt similarly polished affiliate portals, and more campaigns focus on PLM and other engineering systems, the quiet contest over who controls the designs of next-generation hardware will move even further into the criminal underground.

Sources