SU
Ransomware Victim Transportation/Logistics

Sunlight Express Airways

Ransomware attack by Payload Β· Disclosed April 16, 2026 Β· πŸ‡΅πŸ‡­ Philippines

sunlightair.ph

Date Disclosed
Apr 16, 2026
2026
Threat Group
Payload
75 total victims
Industry
Transportation/Logistics

ThreatAI Analysis

Compiled from this incident record and the threat intelligence profile for Payload. Figures and technique mappings are quoted from the source data, not inferred.

About the Payload group

Payload is a ransomware group that emerged in early 2026, using Babuk-derived source code targeting both Windows and ESXi systems with cross-platform double-extortion attacks against healthcare, energy, real estate, and agriculture sectors, claiming 12 victims across seven countries within hours of launching its leak site. Payload has listed 69 victims since February 2026.

How Payload is documented to operate

Native API T1106 Execution

Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Adversaries may abuse these OS API functions as a means of executing behaviors.

Mitigations: Execution Prevention, Behavior Prevention on Endpoint

MITRE ATT&CK reference β†’
Obfuscated Files or Information T1027 Stealth

Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit. This is common behavior that can be used across different platforms and the network to evade defenses. Payloads may be compressed, archived, or encrypted in order to avoid detection. These payloads may be used during Initial Access or later to mitigate detection. Sometimes a user's action may be required to open and Deobfuscate/Decode Files or Information for User Execution. The user may also be required to input a password to open a password protected compressed/encrypted file that was provided by the adversary.

Mitigations: User Training, Behavior Prevention on Endpoint, Antivirus/Antimalware, Audit

MITRE ATT&CK reference β†’
File Deletion T1070.004 Stealth

Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary (ex: Ingress Tool Transfer) may leave traces to indicate to what was done within a network and how. Removal of these files can occur during an intrusion, or as part of a post-intrusion process to minimize the adversary's footprint. There are tools available from the host operating system to perform cleanup, but adversaries may use other tools as well. Examples of built-in Command and Scripting Interpreter functions include <codedel</code on Windows, <coderm</code or <codeunlink</code on Linux and macOS, and rm on ESXi.

MITRE ATT&CK reference β†’
Execution Guardrails T1480 Stealth

Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target. Guardrails ensure that a payload only executes against an intended target and reduces collateral damage from an adversary’s campaign. Values an adversary can provide about a target system or environment to use as guardrails may include specific network share names, attached physical devices, files, joined Active Directory (AD) domains, and local/external IP addresses. Guardrails can be used to prevent exposure of capabilities in environments that are not intended to be compromised or operated within.

Mitigations: Do Not Mitigate

MITRE ATT&CK reference β†’
Process Discovery T1057 Discovery

Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. In Windows environments, adversaries could obtain details on running processes using the Tasklist utility via cmd or <codeGet-Process</code via PowerShell.

MITRE ATT&CK reference β†’
System Information Discovery T1082 Discovery

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture. Adversaries may use this information to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. This behavior is distinct from Local Storage Discovery which is an adversary's discovery of local drive, disks and/or volumes. Tools such as Systeminfo can be used to gather detailed system information. If running with privileged access, a breakdown of system data can be gathered through the <codesystemsetup</code configuration tool on macOS.

MITRE ATT&CK reference β†’

MITRE ATT&CK techniques attributed to Payload across its recorded activity, not a finding about how Sunlight Express Airways was reached.

Incident Analysis

Sunlight Express Airways was targeted by Payload ransomware, one of the most active ransomware groups in our database with 75 confirmed victims globally. The attack was disclosed on April 16, 2026, when Sunlight Express Airways appeared on the group's dark web leak site.

Sunlight Express Airways is based in Philippines , operating in the Transportation/Logistics sector. Philippines ranks #35 globally for ransomware attacks, with 72 victims in our database.

Sector context: Logistics companies are targeted because supply chain disruption has cascading effects on customers and partners, amplifying pressure to pay ransoms quickly to restore operations.

Payload typically employs a double extortion model: first exfiltrating sensitive data from the victim's systems, then deploying ransomware to encrypt files. Victims face two simultaneous threats β€” paying to restore access and paying to prevent publication of stolen data. The group's leak site publishes victim names and exfiltrated data as leverage.

Data source: This incident record is sourced from public ransomware group leak site disclosures aggregated via the ransomware.live API. Disclosure date reflects when the victim was published on the leak site, which may differ from the initial date of compromise. This platform does not publish or link to stolen data. Last data update: Sep 5, 2026 22:00 UTC.

Frequently Asked Questions

Was Sunlight Express Airways attacked by ransomware?

Yes. Sunlight Express Airways was listed as a victim of the Payload ransomware group on April 16, 2026. The organisation is based in Philippines and operates in the Transportation/Logistics sector. The disclosure appeared on the group's dark web leak site.

Which ransomware group attacked Sunlight Express Airways?

Sunlight Express Airways was attacked by Payload ransomware. Payload is one of the most active ransomware groups, having claimed 75 victims globally. The group typically employs a double-extortion model: encrypting the victim's files and threatening to publish stolen data.

When did the Sunlight Express Airways ransomware attack occur?

The ransomware attack on Sunlight Express Airways was disclosed on April 16, 2026. This date reflects when the victim was published on the threat group's leak site, which may differ from the actual date of initial compromise.

What data was stolen in the Sunlight Express Airways ransomware attack?

The specific data stolen from Sunlight Express Airways has not been independently verified by this platform. Ransomware groups typically exfiltrate data before encrypting systems and use the threat of publication to pressure victims. As a Transportation/Logistics organisation, Sunlight Express Airways likely held sensitive business data, client information, and operational records.

How can organisations protect against Payload attacks?

To defend against Payload and similar threat actors, organisations should: maintain regular offline backups tested for restoration; implement network segmentation to limit lateral movement; deploy multi-factor authentication on all remote access; use endpoint detection and response (EDR) tools; conduct regular phishing and security awareness training; and monitor threat intelligence feeds for indicators of compromise (IOCs) associated with active groups.