SODIC A.I CyberSecurity Scoring
SODIC
Company Information
Website:http://www.sodic.com
Employees number:1,672
Number of followers:298,367
NAICS:
Industry Type:Real Estate
Homepage:sodic.com
SODIC Risk Score (AI oriented)
Between 650 and 699
SODICReal Estate
Updated:
26/05/2026
26/05/2026
686/1000
Weak
B
SODIC Global Score (TPRM)
xxxx
SODICReal Estate
Score locked

SODICWeak
Current Score
686B (WEAK)
01000
1 incidents
-90 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
688
MAY 2026
685
APRIL 2026
685
MARCH 2026
683
FEBRUARY 2026
770
Ransomware
01 Feb 2026 • SODIC
SODIC: Ransomware Uses ChaCha20 and Curve25519 to Encrypt Windows Files
New Payload Ransomware Emerges with Advanced Encryption and Anti-Forensics Tactics
680
CRITICAL-90
SOD1779776631
New Payload Ransomware Emerges with Advanced Encryption and Anti-Forensics Tactics
A sophisticated new Windows ransomware strain, Payload, has surfaced in early 2026, employing a potent combination of ChaCha20 stream encryption and Curve25519 ECDH key exchange to render victim data irrecoverable without the attackers’ private key. The malware also integrates aggressive anti-forensics measures, including ETW patching, VSS deletion, event log wiping, and process termination, to evade detection and hinder recovery efforts.
First observed in February 2026, Payload quickly adopted a double-extortion model, stealing data before encryption and leveraging dedicated leak sites to pressure victims. Within weeks, the group claimed targets across Egypt, Mexico, Poland, and other regions, demonstrating a rapid global expansion. Its debut victim, SODIC, a major Egyptian real estate developer, marked the first public indication of Payload’s operations and infrastructure.
As of 24 March 2026, the group’s leak site listed 50 victims, with recent attacks targeting A-Sonic Logistics Solutions, underscoring a focus on high-disruption sectors like logistics and supply chains. While Payload’s targeting is opportunistic, key industries include:
- Logistics and transportation (e.g., freight and supply-chain firms)
- Real estate and construction (particularly in Egypt and the MENA region)
- Manufacturing, professional services, and technology
The ransomware’s encryption process generates a unique key per file using Curve25519 ECDH, with ephemeral private keys wiped from memory to prevent recovery. Encrypted files are renamed with the .payload extension and appended with an RC4-encrypted footer containing key handoff data. Ransom notes (RECOVER_payload.txt) direct victims to Tor-based negotiation and leak sites, imposing strict deadlines (72 hours for initial contact, 240 hours for full negotiation) under threat of data publication.
Payload’s binary includes 14 command-line flags for customization, enabling features like SIMD acceleration, thread control, and self-deletion. It enforces single-instance execution via a mutex named MakeAmericaGreatAgain and employs direct NT APIs for parallel file encryption while terminating critical processes and services to maximize damage.
Indicators of Compromise (IOCs):
- MD5: E0FD8FF6D39E4C11BDAF860C35FD8DC0
- SHA256: 1CA67AF90400EE6CBBD42175293274A0F5DC05315096CB2E214E4BFE12FFB71F
- Mutex: MakeAmericaGreatAgain
- File extension: .payload
- Ransom note: RECOVER_payload.txt
- Tor sites:
- Leak site: payloadrz5yw227brtbvdqpnlhq3rdcdekdnn3rgucbcdeawq2v6vuyd[.]onion
- Negotiation portal: payloadynyvabjacbun4uwhmxc7yvdzorycslzmnleguxjn7glahsvqd[.]onion
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JANUARY 2026
770
DECEMBER 2025
769
NOVEMBER 2025
769
OCTOBER 2025
769
SEPTEMBER 2025
769
AUGUST 2025
769
JULY 2025
769
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for SODIC ??
What was SODIC's A.I Rankiteo Cyber Score in May 2026 ??
What was SODIC's A.I Rankiteo Cyber Score in April 2026 ??
What was SODIC's A.I Rankiteo Cyber Score in March 2026 ??
What was SODIC's A.I Rankiteo Cyber Score in February 2026 ??
What was SODIC's A.I Rankiteo Cyber Score in January 2026 ??
What was SODIC's A.I Rankiteo Cyber Score in December 2025 ??
What was SODIC's A.I Rankiteo Cyber Score in November 2025 ??
What was SODIC's A.I Rankiteo Cyber Score in October 2025 ??
What was SODIC's A.I Rankiteo Cyber Score in September 2025 ??
What was SODIC's A.I Rankiteo Cyber Score in August 2025 ??
What was SODIC's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on SODIC's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with SODIC ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view SODIC's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?