TaiG, also known as the TaiG Jailbreak Team, was a Chinese iOS jailbreak developer group active during the iOS 7 and iOS 8 era. The group is known for producing public jailbreaks and for discovering or operationalizing multiple Apple security vulnerabilities that were later assigned CVE identifiers and credited to the team. TaiG is not a conventional intrusion set or ransomware actor; it is best characterized as a jailbreak development team focused on defeating Apple platform security controls to obtain persistent privileged code execution on iOS devices. TaiG’s work centered on post-exploitation and persistence mechanisms required to maintain a jailbreak across reboots and security boundaries. Reported techniques associated with the team include reuse of incomplete fixes to Apple code-signing bypasses, abuse of dyld and AMFI-related trust mechanisms, and use of kernel vulnerabilities to support jailbreak chains. TaiG has been linked to reuse of the so-called Patient ALPHA code-signing bypass lineage after Apple’s earlier remediations were found to be incomplete, as well as reuse of kernel address disclosure techniques involving Mach interfaces. Public reporting also associates TaiG with leveraging weaknesses that enabled unsigned code execution, privilege escalation to system level, and persistence of modified execution flows on jailbroken devices. The group is part of a broader shift in public jailbreak development from earlier Western teams to Chinese teams such as Pangu and TaiG. TaiG is frequently discussed alongside other jailbreak teams including evad3rs and Pangu because their jailbreak chains built on related classes of Apple platform weaknesses, especially code-signing bypasses, kernel bugs, and KASLR-relevant information leaks. Available information supports China as the group’s operating geography. There is no high-confidence evidence here that TaiG conducted espionage, ransomware, destructive attacks, or broad criminal intrusion operations beyond jailbreak development.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Identified as a vulnerability reporter credited with multiple iOS security issues affecting filesystem access, code signing, and privilege escalation paths associated with jailbreak research.
Created iOS jailbreaks by exploiting repeatedly incomplete Apple fixes, using other kernel bugs and reusing mach_port_kobject-based address deobfuscation techniques.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.