2026-08-06 (THURSDAY): Hazy Scorpius Exploitation of CVE-2026-12569 AUTHOR: - Matt Brady REFERENCES: - https://www.linkedin.com/posts/unit42_we-are-monitoring-exploitation-of-cve-2026-activity-7491575680099545088-jqI4/ - https://x.com/Unit42_Intel/status/2085809982721740930 NOTES: - We've discovered multiple files that are JSP web shells designed to target PTC Windchill PLM servers vulnerable to CVE-2026-12569. -- PTC issued a security advisory in June 2026 about the vulnerability at: https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability -- PTC has issued security patches, and the advisory contains indicators of recent exploitation attempts. - PTC information and public reporting indicate this activity is associated with the CLOP ransomware group, a threat actor we track as Hazy Scorpius. -- Reference: https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/ - The web shells authenticate incoming HTTP requests by reading the custom header X-windchill-req, which must be exactly 8 characters matching the string ?x8Fmgow -- with the first character replaced by a letter representing one of eight commands listed below: --- J (class loading) --- D (file exfiltration) --- S (credential theft) --- L (file vault enumeration) --- G (file read) --- R (file deletion) --- E (echo) --- O (OS fingerprinting) - Command parameters are passed via the X-windchill-prm HTTP header or the HTTP parameter a for binary payloads. - Based on threat hunting, we suspect this activity has targeted and potentially impacted organizations operating across numerous sectors and located in various countries, primarily the United States. BACKGROUND: - Hazy Scorpius is a financially-motivated threat group active since at least February 2019. - Hazy Scorpius is known for its sophisticated intrusion operations and large-scale data theft and extortion attacks. - The group traditionally used its CLOP ransomware to extort organizations, with an average ransom demand around $27M. - Initial access was typically obtained by exploiting zero-day vulnerabilities in file transfer software, such as MOVEit in 2023 and Cleo in 2024. -- https://unit42.paloaltonetworks.com/threat-brief-moveit-cve-2023-34362/ -- https://www.cybereason.com/blog/cve-2024-55956-cleo-vulnerability - However, the group pivoted to extortion without encryption in August 2025. -- This started as part of its exploitation of a vulnerability (CVE-2025-61884) in Oracle’s E-Business Suite (EBS) software. -- Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-61884 - This campaign represents the latest example of data theft and extortion operations without encryption by financially motivated threat actors. -- The observed tradecraft overlaps significantly with activity previously attributed to Hazy Scorpius. -- Reference: https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks/ - Given the attackers' history of rapid, widespread campaigns, organizations using PTC Windchill and PTC FlexPLM software should immediately: -- Hunt for signs of compromise -- Deploy appropriate mitigations to reduce their risk for data theft and extortion. INDICATORS: IP ADDRESSES: Note: These IP addresses may not be inherently malicious, but they are indicators of network activity associated with exploitation activity so they should be heavily scrutinized. - 5.180.41[.]35 - 74.50.76[.]146 - 118.99.107[.]116 - 209.222.98[.]44 2 RELATED SAMPLES (READ SHA256 HASH - FIRST SEEN DATE): 55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c - N/A 321e1fb01eb3462b48ff6ccdef132acc1182e3f7456548439f0d4ead12fd98bf - 2026-07-27