SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefSunday, July 26, 2026 INTEL CONFIDENCE 70% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Cl0p Exploits Exposed PTC Windchill Enterprise Software | CRITICAL |
|
5 C2 IPs | 0 OTX IOCs | 11 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is dominated by active exploitation of critical unauthenticated remote code execution (RCE) vulnerabilities in enterprise software, specifically targeting Alibaba Fastjson 1.x and PTC Windchill/FlexPLM. Concurrently, sophisticated malvertising campaigns (such as SourTrade) are utilizing browser-side assembly of executables to bypass traditional network detection, while Cl0p ransomware affiliates actively target exposed PLM systems. |
|
■ CRITICAL STORIES Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE Threat actors associated with the Cl0p ransomware group are actively exploiting unauthenticated remote code execution (RCE) flaws in internet-facing PTC Windchill and FlexPLM deployments for data extortion, threatening industrial and manufacturing supply chains. |
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Active exploitation has been detected targeting a critical unauthenticated RCE vulnerability in Alibaba's Fastjson 1.x library within Spring Boot applications, leaving organizations highly vulnerable as no official patch is currently available. |
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable The 'SourTrade' malvertising campaign uses browser-side JavaScript and a legitimate Bun runtime base to construct malicious Windows executables directly on the victim's machine, effectively evading network-level file detection. |
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git A public proof-of-concept exploit has been released for a previously patched GitLab RCE vulnerability, enabling authenticated users to execute arbitrary commands as the 'git' user on unpatched self-managed instances. |
|
■ CVEs IDENTIFIED [CVE-TBD] Alibaba Fastjson 1.x — Unauthenticated Remote Code Execution in Spring Boot applications |
[CVE-TBD] GitLab Self-Managed — Remote Code Execution allowing authenticated users to run commands as git |
[CVE-TBD] PTC Windchill & FlexPLM — Unauthenticated Remote Code Execution exploited by Cl0p affiliates |
[CVE-TBD] Rockwell Automation Arena Simulation Software — Code execution vulnerabilities via malicious project files |
|
■ THREAT ACTORS Cl0p (Chubby Scorpius / FIN11 / Graceful Spider / Lace Tempest) | Ransomware Group |
Exploiting unauthenticated RCE flaws in internet-exposed PTC Windchill and FlexPLM for data extortion. |
ShinyHunters | Cybercrime Group / Extortionist |
Leaking data used by secondary threat actors to conduct $2,000 Bitcoin sextortion email scams. |
DevMan Operators | Ransomware-as-a-Service (RaaS) |
Maintaining a centralized portal for payload builds, affiliate payouts, and victim management. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Used to target unpatched GitLab instances, Fastjson 1.x, and PTC Windchill/FlexPLM deployments. |
| T1027.004 | | Compile After Delivery | Observed in SourTrade and JavaScript-based malvertising campaigns assembling malware directly in browser memory. |
| T1204.001 | | User Execution: Malicious Link | Used in Steam forum ClickFix campaigns and malvertising to lure users to malicious pages. |
| T1566.002 | | Phishing: Spearphishing Link | Used in sextortion campaigns leveraging leaked ShinyHunters data. |
| T1486 | | Data Encrypted for Impact | Associated with Cl0p and DevMan ransomware operations. |
| T1496 | | Resource Hijacking | Deployment of XMRig cryptominers via compromised Steam forums. |
|
■ PATCH PRIORITY Alibaba — Fastjson 1.x — Active exploitation of unpatched RCE in Spring Boot applications — ThreatBook / Imperva |
PTC — Windchill & FlexPLM — Unauthenticated RCE actively exploited by Cl0p ransomware affiliates — The Hacker News |
GitLab — GitLab Self-Managed — Public PoC released for authenticated RCE running commands as git — depthfirst / The Hacker News |
Rockwell Automation — Arena Simulation Software — Code execution flaws via malicious project files — SecurityWeek |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Deploy web application firewall (WAF) rules to block malicious JSON requests targeting Alibaba Fastjson 1.x, as no official patch is currently available. |
| 2 | [P1] Immediately patch all self-managed GitLab instances to version 18.11.3 or higher to mitigate the newly published authenticated RCE exploit. |
| 3 | [P1] Audit and restrict internet exposure of PTC Windchill and FlexPLM deployments, and apply vendor-provided security updates to prevent Cl0p ransomware exploitation. |
| 4 | [P2] Apply security patches issued by Rockwell Automation for Arena Simulation Software to prevent arbitrary code execution via malicious project files. |
| 5 | [P2] Implement browser security controls and content filtering to block unauthorized execution of local runtimes (like Bun) initiated via malvertising scripts. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |