Clop-Webshell in PTC Windchill: erbeutet Credentials und plant Lateral Movement
LONDON (IT BOLTWISE) – Eine neu entdeckte JSP-Webshell nutzt eine kritische Schwachstelle in PTC Windchill und FlexPLM, um Credentials aus dem Keystore zu entschlĂĽsseln. Die Malware blendet sich dabei als anwendungsspezifischer Implantats-Workflow ein und greift auf APIs, Datenbankschema und Datei-„Vaults“ zu. Laut einer Bewertung werden damit nicht nur Konten entwendet, sondern auch Pfade fĂĽr Lateral […]


#Sophos