The observed attack chain begins with reconnaissance against the FlexPLM WSDL endpoint, followed by exploitation of the information disclosure vulnerability and CVE-2026-12569, a deserialization flaw that enables unauthenticated remote code execution. Attackers deploy hex-named JSP webshells under the /Windchill/login/ directory, allowing persistent remote access to compromised servers.
Following initial compromise, attackers enumerate the filesystem, generate file listings (commonly using flst.txt), and stage sensitive engineering and design data for exfiltration. Victims are subsequently targeted with large-scale extortion emails sent from compromised accounts, claiming responsibility for the breach and threatening public release of stolen data unless ransom demands are met. The campaign has primarily targeted organizations with internet-exposed Windchill and FlexPLM deployments.