Pangu Team is a Chinese offensive security and jailbreak research team best known for developing public iOS jailbreaks, including Pangu7 and Pangu8, and for advanced vulnerability research against Apple platforms. The group is associated with Chinese exploit development talent and has been described as one of China’s most prominent offensive security teams. Pangu has also been linked to Pwnzen Infotech and identified as a subsidiary or component of Qi Anxin in reporting on China’s private-sector offensive cyber ecosystem. Pangu’s publicly documented activity centers on discovering, acquiring, and operationalizing Apple platform vulnerabilities, especially kernel flaws, code-signing bypasses, and techniques that enable jailbreak persistence. Research discussing Pangu’s jailbreaks has highlighted the team’s reuse of incompletely patched Apple vulnerabilities, including variants of the code-signing bypass known as Patient ALPHA, combined with new kernel bugs. Pangu has also been associated with exploitation of kernel address disclosure weaknesses and other low-level primitives useful for defeating platform protections and maintaining post-exploitation persistence on iOS devices. The team sits within a broader Chinese vulnerability research and offensive security pipeline that has connected commercial security firms, exploit competitions, and training ecosystems. Pangu has been referenced in connection with Android challenge development for offensive security competitions and with Chinese exploit-development circles that overlap with state-adjacent and defense-contractor environments. Available information supports characterizing Pangu as a highly capable exploit-development team focused on initial compromise and post-compromise enablement on mobile platforms, with strong emphasis on privilege escalation, persistence, and defense-evasion through code-signing bypass and related techniques. Although Pangu is widely known for jailbreak development rather than ransomware or extortion activity, its work demonstrates sophisticated offensive capability relevant to surveillance and state-linked exploitation. High-confidence reporting supports a China nexus, but direct evidence in the supplied material does not establish specific victim-country targeting by Pangu itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An offensive security team under Qi Anxin, known globally for mobile exploitation and mentioned as part of the talent and contractor ecosystem surrounding i-Soon.
Referenced as a named jailbreak research group credited in discovery of a kernel information disclosure issue affecting kernel memory layout.
Produced multiple iOS jailbreaks by reusing incompletely fixed code-signing bypasses and kernel vulnerabilities; also used the mach_port_kobject master-port trick in public jailbreaks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.