Chinese-Linked Hackers Leverage SharePoint Vulnerabilities to Deploy Ransomware in Latin America

The threat group Warlock, believed to be operating from China, is actively exploiting Microsoft SharePoint vulnerabilities to disable security defenses and distribute ransomware across organizations in Portuguese and Spanish-speaking regions. Symantec and Carbon Black researchers have documented attacks targeting critical infrastructure, government agencies, and educational institutions. The campaign demonstrates ongoing exploitation of both known and zero-day SharePoint flaws for maximum operational impact.
Security researchers at Symantec and Carbon Black have identified a coordinated campaign by the threat actor Warlock, which operates with suspected ties to China. The group has been systematically targeting organizations across Latin America by capitalizing on weaknesses in Microsoft's SharePoint platform. Their approach involves exploiting both publicly disclosed vulnerabilities and previously unknown flaws to gain initial access and establish footholds within victim networks.
The attacks have focused on high-value sectors including critical infrastructure operators, government bodies, and educational organizations in countries where Portuguese and Spanish are primary languages. Once inside networks, the hackers disable security mechanisms before deploying ransomware, a tactic that maximizes the likelihood of successful encryption and extortion. This multi-stage approach reflects a sophisticated understanding of enterprise security architectures.
Organizations across Latin America face potential operational disruption and data compromise if targeted by this campaign. Critical infrastructure providers could experience service interruptions affecting broader populations, while government agencies may lose access to sensitive systems and information. Educational institutions could see research and student data compromised. The attacks may also encourage other threat groups to exploit similar SharePoint vulnerabilities, potentially expanding the overall risk landscape for businesses and institutions worldwide that rely on this widely deployed platform.