Online Security & Privacy

The High-Stakes Facade of IRIS C2: Convicted Fraudsters Pivot to the Zero-Day Exploit Market

A new cybersecurity venture claiming to operate out of McLean, Virginia, is making waves in the high-stakes world of offensive digital weaponry by offering multi-million dollar payouts for "zero-day" software vulnerabilities. The company, known as IRIS C2, has aggressively marketed itself on social media since early 2025, promising as much as $7 million for the most potent exploits. However, an investigation into the firm’s leadership reveals a foundation built on a history of federal crimes, elaborate political hoaxes, and a pattern of operating under assumed identities. IRIS C2 is the latest project of Jacob Wohl and Jack Burkman, two notorious figures whose previous exploits involve a series of failed intelligence firms, fraudulent investment schemes, and a massive robocall operation designed to suppress voter turnout.

The Business Model of IRIS C2

IRIS C2 first emerged on the social media platform X (formerly Twitter) in January 2025 under the handle @C2IRIS. Since its inception, the account has cultivated a following of over 4,000 users by posting technical commentary on software exploits, artificial intelligence, and offensive security. The company positions itself as a premier destination for "vulnerability researchers and exploit developers," specifically targeting "junior engineers with raw talent" and "extremely high IQ." Notably, the company’s recruitment messaging emphasizes that it does not require formal education or industry experience, a tactic often used to attract younger, less-vetted talent who may be more susceptible to high-risk employment arrangements.

The IRIS C2 website details a tiered payout structure for "zero-day" exploits—vulnerabilities in software that are unknown to the vendor and for which no patch exists. These capabilities are highly prized by intelligence agencies and cyber-mercenary groups. IRIS C2 claims to be interested in acquiring full "exploit chains" across all major platforms, including iOS, Android, and Windows. The promised rewards range from $10,000 for minor bugs to $7 million for high-value, reliable capabilities. This price point places IRIS C2 in direct competition with established "gray market" exploit brokers like Zerodium and Crowdfense, yet IRIS C2 lacks the transparency and established reputation typically required to navigate the sensitive world of government defense contracting.

Identifying the Leadership: Calvexa Group and the Wohl-Burkman Connection

Public records and government contracting portals provide the first clues into the true nature of IRIS C2. According to G2Exchange, a portal for federal contractors, the domain irisc2.com is operated by a Virginia-based entity called Calvexa Group LLC. While Calvexa is registered as a federal contractor, there is currently no public evidence that the firm holds any active direct government contracts. The physical address listed for Calvexa Group LLC in Arlington, Virginia, belongs to Jack Burkman, a 60-year-old lobbyist and the founder of Burkman & Associates.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

When questioned about the operations of IRIS C2, Burkman directed inquiries to his long-term partner, 28-year-old Jacob Wohl. Wohl, who has often been the public face of their various joint ventures, confirmed in interviews that he is heavily involved in the day-to-day operations. Despite his lack of formal training in computer science, Wohl claimed to possess "spectacularly exquisite capabilities" in the tech field. He asserted that IRIS C2 employs approximately 40 individuals, though he noted that none are permitted to list the company on professional networking sites like LinkedIn, citing "operational security."

A Chronology of Deception: The Founders’ Legal History

The involvement of Wohl and Burkman in the cybersecurity sector is particularly alarming given their extensive history of legal infractions and deceptive practices. Their partnership has been defined by a series of "dirty tricks" campaigns and financial frauds spanning over a decade.

The "Wohl of Wall Street" Era

Jacob Wohl’s history of fraud began in his teens. By the age of 17, he had branded himself the "Wohl of Wall Street," appearing on national news outlets to discuss his hedge funds. However, in 2017, the Arizona Corporation Commission charged Wohl and his investment funds with 14 counts of securities fraud. He was eventually ordered to pay $35,000 in restitution. In 2019, Wohl pleaded guilty in California to four felony counts related to the sale of unregistered securities, resulting in two years of probation.

Political Hoaxes and Disinformation

Throughout the late 2010s, Wohl and Burkman orchestrated a series of high-profile, failed attempts to frame public figures. These included fabricating sexual assault allegations against then-FBI Director Robert Mueller and South Bend Mayor Pete Buttigieg. They also held press conferences to spread false claims regarding the personal lives of Senators Elizabeth Warren and Kamala Harris. These campaigns were largely characterized by the use of "fake intelligence companies" designed to give a veneer of legitimacy to their fabrications.

The 2020 Robocall Scheme

In the aftermath of the 2020 U.S. presidential election, the pair faced their most significant legal challenges to date. They were prosecuted in multiple states for orchestrating a robocall campaign that targeted minority neighborhoods in battleground states. The calls disseminated false information about mail-in ballots, suggesting that voter data would be used by law enforcement to track old warrants or by the CDC to track mandatory vaccinations. In Ohio, both pleaded guilty to felony telecommunications fraud. In 2023, the Federal Communications Commission (FCC) issued a record-breaking $5.1 million fine against them for these activities. By late 2025, after several appeals, they were sentenced to probation for their roles in the voter suppression scheme.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

The LobbyMatic Precedent and Pseudonym Use

The shift toward IRIS C2 follows the collapse of their previous venture, LobbyMatic. As reported by Politico in late 2024, LobbyMatic was marketed as an AI-driven lobbying platform. However, it was later revealed that Wohl and Burkman were running the company using pseudonyms—"Jay Klein" and "Bill Sanders," respectively. Several employees resigned in protest after discovering the true identities of their bosses. This pattern of using aliases and shell companies suggests that the secrecy surrounding IRIS C2’s 40 alleged employees may be less about national security and more about masking the involvement of the company’s founders.

Connections to International Cybercrime

Further complicating the reputation of IRIS C2 are reports connecting Wohl and Burkman to high-profile cybercriminals. In March 2024, investigative reports indicated that the pair had been paid a $300,000 retainer by a Canadian individual accused of a $65 million cryptocurrency theft involving platforms like KyberSwap and Indexed Finance. The retainer was reportedly intended to fund a campaign to secure a presidential pardon for the accused hacker. This involvement with the proceeds of alleged cybercrime highlights the murky ethical waters in which IRIS C2 operates.

Analysis: Implications for the Cybersecurity Industry

The emergence of IRIS C2 raises significant concerns for the cybersecurity industry and national security. The market for zero-day exploits is inherently dangerous; in the wrong hands, these tools can be used to facilitate state-sponsored espionage, disrupt critical infrastructure, or enable massive ransomware attacks.

1. The Risk of "Gray Market" Volatility

Legitimate exploit brokers typically have rigorous vetting processes for both their researchers and their clients. By dangling millions of dollars with few apparent barriers to entry, IRIS C2 may attract researchers who are unable to pass the background checks of more reputable firms. This creates a "wild west" environment where sensitive digital weapons are traded by individuals with a documented history of fraud.

2. Disinformation and Offensive Cyber

Given Wohl and Burkman’s history with influence operations and disinformation, the pivot to offensive cyber capabilities is a logical, if dangerous, evolution. The ability to combine technical exploits with sophisticated disinformation campaigns represents a potent threat to democratic processes and corporate stability.

Felons, Fraudsters Flog Offensive Cybersecurity Startup

3. Trust and Transparency

The cybersecurity community relies heavily on trust. The use of pseudonyms, the lack of verifiable employees, and the founders’ criminal records make IRIS C2 an outlier in the industry. For researchers, the risk of "selling" a multi-million dollar exploit to a company run by convicted fraudsters is high—there is no guarantee of payment, and the ultimate destination of the exploit remains unknown.

Official Responses and Current Status

While IRIS C2 continues to post updates on its social media channels, official government agencies have remained largely silent on the company’s claims of federal contracting. The McLean, Virginia, office remains a point of contention, as records still point back to Burkman’s personal property in Arlington.

Industry analysts suggest that the brazenness of IRIS C2’s public profile is a departure from the "quiet professionalism" usually associated with the offensive security sector. Most firms in this space avoid the spotlight to protect their methods and their clients. The high-volume, high-visibility approach of Wohl and Burkman suggests that IRIS C2 may be as much about "clout-chasing" and brand-building as it is about genuine technical capability.

As of mid-2025, IRIS C2 remains active online, continuing to solicit "the world’s best" researchers. However, for the cybersecurity community, the company serves as a stark reminder of the complexities and risks inherent in the global trade of digital vulnerabilities. With founders whose careers are defined by fabrication and fraud, the true "operational value" of IRIS C2 remains deeply in question.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button