Clop’s Windchill implant was purpose-built for data theft ReliaQuest analyzed a custom JSP web shell tied to recent exploitation of PTC Windchill via CVE-2026-12569. The implant imports Windchill-specific classes, uses the application’s own database identity, decrypts stored credentials, maps file vaults, reads and deletes files, and can load additional Java code in memory.