ctipilot.ch
← Back to Weekly 2026-W34
NOTABLEexploitedupdateNATOB2synthesis

UPDATE — Cl0p Windchill campaign status: the implant is now reverse-engineered and one command is shown to return the whole application keystore in plaintext, while the named-victim count has stopped moving and one heavyweight name quietly left the leak site

discovered 2026-08-23 23:59 UTCrun 2026-08-23T2311Z-weekly2 sourcesmulti-source

UPDATE · originally covered Cl0p PTC Windchill campaign status: the extortion wave crossed from leak-site assertion to partial victim corroboration this week — Philips and Shell responded, European organisations appeared among the named listings, and a second vendor confirmed the webshell artefact PTC had already documented (2026-08-16)

the prior weekly recorded this campaign crossing from leak-site assertion to partial victim corroboration — Philips and Shell responding, European organisations among the listings, a second vendor corroborating the web-shell artefact PTC had already documented. This week the assertion side has gone quiet and the technical side has opened up.

The implant is documented, and the credential exposure is now specific. ReliaQuest's reverse engineering, published 2026-08-18, states the activity was highly likely conducted by Cl0p and describes something purpose-built against Windchill rather than a generic shell. The single most consequential capability is a credential dump: "A single \"S\" command to the web shell returns Windchill's directory-management and administrative credentials in plaintext" — implemented by reading the application's configuration file, decrypting the LDAP manager password from the keystore, and then iterating every remaining stored property to decrypt administrative account credentials, object-storage credentials and all site administrator keys (ReliaQuest, 2026-08-18). That converts a single application compromise into a directory compromise wherever the LDAP manager account governs authentication for the wider estate. Two further properties matter for anyone hunting: commands arrive in a custom HTTP request header rather than in a URL or body, so controls inspecting only paths and parameters see no command traffic at all; and the implant's database queries run through Windchill's own connection classes, so database telemetry attributes the theft to the application's normal service identity.

The victim list has stopped growing. Follow-on coverage through 2026-08-21 adds no new named victims and no new technical developments, and the count that has been in circulation since 2026-08-15 — in the low-to-mid forties, with different trackers and outlets disagreeing by one or two — has not moved. ISMG's own framing puts the group's claim at more than 40 firms (GovInfoSecurity, 2026-08-17). A plateau is not evidence that exploitation has stopped; Cl0p's historical pattern is to publish in batches, and ReliaQuest assesses with high confidence that exploitation will expand to more organisations in the coming weeks.

One name left the list, and two more bounded their exposure. ISMG reports that "GE is no longer on Clop's darkweb leak site of companies that have not contacted it to negotiate a payoff", framing the removal as consistent with either a ransom payment or a resumed negotiation (GovInfoSecurity, 2026-08-17). This run could not find a second outlet that checked the listing itself, so that observation is one outlet's and is carried as such — but it is worth recording precisely because it is the only publicly visible signal of a negotiation outcome anywhere in this campaign. Two other named companies gave first statements to the same outlet, both bounding rather than denying: Toast, from which the group claims files, said "Toast identified unauthorized access to a limited number of files; to date, the files identified contain nonsensitive internal documents," adding that it isolated the affected systems the same day it detected the activity and considers the situation contained; Fiserv, from which the group claims 874 gigabytes including computer-aided design files, said none of its customer, bank, transaction or personal data were stolen based on a comprehensive review to date (GovInfoSecurity, 2026-08-17).

A single "S" command to the web shell returns Windchill's directory-management and administrative credentials in plaintext

ReliaQuest Threat Research Team 2026-08-18

GE is no longer on Clop's darkweb leak site of companies that have not contacted it to negotiate a payoff.

GovInfoSecurity (ISMG) 2026-08-17

Toast identified unauthorized access to a limited number of files; to date, the files identified contain nonsensitive internal documents,

Toast spokesperson, quoted by GovInfoSecurity (ISMG)

ATT&CK mapping

6 techniques mapped from the cited reporting · MITRE ATT&CK v19.2

Initial Access TA0001
T1190Exploit Public-Facing Application

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

overlap matrix · ATT&CK page ↗

Persistence TA0003
T1505.003Server Software Component: Web Shell

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

overlap matrix · ATT&CK page ↗

Credential Access TA0006
T1552.001Unsecured Credentials: Credentials In Files

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

overlap matrix · ATT&CK page ↗

T1555Credentials from Password Stores

Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in several places on a system, depending on the operating system or application holding the credentials. There are also specific applications and services that store passwords to make them easier for users to manage and maintain, such as password managers and cloud secrets vaults. Once credentials are obtained, they can be used to perform lateral movement and access restricted information.

overlap matrix · ATT&CK page ↗

Exfiltration TA0010
T1041Exfiltration Over C2 Channel

Adversaries may steal data by exfiltrating it over an existing command and control channel. Stolen data is encoded into the normal communications channel using the same protocol as command and control communications.

overlap matrix · ATT&CK page ↗

Impact TA0040
T1657Financial Theft

Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for victims. Financial theft is the ultimate objective of several popular campaign types including extortion by ransomware, business email compromise (BEC) and fraud, "pig butchering," bank hacking, and exploiting cryptocurrency networks.

overlap matrix · ATT&CK page ↗

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.