# Convicted Felons Behind Offensive Cybersecurity Startup Offering Millions for Zero-Day Exploits


A newly launched cybersecurity firm promising million-dollar payouts for software exploits is owned and operated by Jack Burkman and Jacob Wohl—a pair of convicted felons with a documented history of orchestrating disinformation campaigns, falsifying intelligence reports, and conducting illegal election-interference robocall schemes. The firm, IRIS C2, presents itself as a legitimate zero-day acquisition operation while being rooted in the same operations infrastructure used in prior fraudulent ventures.


## The Operation: IRIS C2's Public Face


IRIS C2 launched publicly in January 2025 with an X/Twitter account (@C2IRIS) that has accumulated over 4,000 followers. The company presents itself as a Virginia-based offensive cybersecurity firm actively recruiting vulnerability researchers and exploit developers worldwide.


The firm's core marketing pitch is direct: it promises to pay security researchers for zero-day exploits, with compensation structured tiered by target, reliability, and operational value:


  • $10,000 to $7 million for zero-day exploits targeting major platforms
  • Additional acquisition categories including "individual primitives" and "partial chains"
  • Emphasis on acquiring capabilities across all major operating systems

  • The company's LinkedIn profile and website (irisc2.com) emphasize recruitment, claiming to have received overwhelming volumes of applications from vulnerability researchers and junior engineers with "raw talent" and "extremely high IQ"—deliberately appealing to early-career talent who may prioritize high payouts over reputational concerns.


    ## Background and Context: The Burkman-Wohl Operation


    The existence of IRIS C2 under Burkman and Wohl's control raises immediate red flags given their extensively documented criminal history in coordinating disinformation and election interference campaigns.


    Key incidents in their documented record:


    | Incident | Date | Outcome |

    |----------|------|---------|

    | FBI Director Robert Mueller defamation campaign | 2018 | Press conference featuring fabricated sexual assault allegations |

    | Mayor Pete Buttigieg defamation campaign | 2019 | False claims disseminated via fake intelligence front |

    | Senator Elizabeth Warren/Kamala Harris affair allegations | 2019 | False allegations and press conferences |

    | 2020 election robocall scheme | 2020-2021 | 15 felony counts in Ohio; additional state prosecutions |

    | FCC robocall violations | 2023 | $5.1 million fine (largest in FCC history at time) |

    | Federal civil rights lawsuit settlement | 2023 | $1 million settlement for civil rights violations |

    | Felony telecommunications fraud plea | 2022 | Ohio guilty plea; probation and fines imposed |

    | 2020 election robocall sentencing | 2025 | Probation sentences after appeal rejections |


    The pattern reflects a systematic approach to creating fraudulent front organizations—fake intelligence firms, shell companies with assumed names, and digital platforms—to amplify disinformation at scale. IRIS C2 operates within this same infrastructure.


    ## Who Runs IRIS C2


    Jack Burkman, 60, is the founder and managing partner of Burkman & Associates, a registered lobbying firm. Business records show that his Arlington, Virginia address—listed in incorporation documents for IRIS C2's parent entity, Calvexa Group LLC—is the operational address for his lobbying operation.


    Jacob Wohl, 28, Burkman's longtime associate, has been present for nearly every major disinformation operation the pair has coordinated. When contacted for comment about IRIS C2, Burkman immediately deferred to Wohl, indicating Wohl's active role in day-to-day management.


    Federal contractor status: Government procurement portal G2Exchange lists Calvexa Group LLC as a registered federal contractor, though it shows no active direct government contracts at present.


    ## IRIS C2's Business Model and Technical Claims


    The company publicly claims to operate as a zero-day acquisition and exploitation capability provider—effectively a commercial broker in offensive cyber capabilities. This business model would position IRIS C2 as:


  • An intermediary acquiring unpatched vulnerabilities from researchers
  • An aggregator and refinement entity for exploit chains and "primitives" (reusable exploitation components)
  • A potential re-seller of capabilities to government, private sector, or international clients

  • The stated acquisition focus on "all major platforms" suggests no geographic, sectoral, or technical limitations—an unusually broad scope for legitimate defensive research partnerships.


    ## Verification and Regulatory Status


    Independent verification through government procurement records confirms:


  • Registration as federal contractor: Calvexa Group LLC appears in G2Exchange
  • No active government contracts: Despite contractor status, no current procurement records are listed
  • Address verification: Arlington property is confirmed as Burkman's operational location
  • Entity connection: The Calvexa Group website (calvexagroup.com) directly forwards to IRIS C2's domain

  • The federal contractor registration itself is unusual given the principals' criminal convictions, which typically trigger debarment reviews in federal procurement.


    ## Technical and Operational Concerns


    Several structural concerns emerge regarding IRIS C2's claimed operations:


    1. Exploit Chain Integrity

    The acquisition of "partial chains" and "primitives" without documented verification frameworks raises questions about whether acquired capabilities are verified, tested, or validated before deployment.


    2. Source Verification

    A flat-fee acquisition model creates incentives for researchers to submit unverified, exaggerated, or non-functional exploits. Without transparent validation, the firm's reliability claims cannot be independently assessed.


    3. Operational Security

    The public recruitment of exploit developers through social media, combined with transparent payout structures, creates a detailed signature of IRIS C2's capabilities—valuable intelligence for both defenders and competitor threat actors.


    4. Regulatory Compliance

    Export control regulations (ITAR, EAR) restrict the transfer of offensive cyber capabilities to foreign nationals and certain entities. A globally-recruiting exploit acquisition firm must navigate complex compliance frameworks that remain unaddressed in their public materials.


    ## Implications for Security Researchers and Organizations


    For security researchers: The promises of high payouts should be weighted against several reputational and legal risks. Selling exploits to unverified buyers creates liability, including potential legal consequences if capabilities are used in sanctions evasion, human rights violations, or domestic crimes. The principals' documented history suggests minimal ethical constraints on exploit deployment.


    For organizations and security teams: IRIS C2's existence and operational model should trigger defensive priorities:


  • Assume advanced capabilities exist: If IRIS C2 acquires even a fraction of submitted exploits, defenders should assume sophisticated adversaries have access
  • Accelerate vulnerability disclosure processes: Faster patching reduces the window for acquired exploits to maintain utility
  • Monitor recruitment signals: Tracking IRIS C2's public hiring and exploit acquisition claims provides early warning of emerging capabilities

  • ## HackWire Analysis


    This is not a typical startup story. IRIS C2 represents a systematization of the same operational infrastructure Burkman and Wohl have repeatedly weaponized—creating seemingly legitimate entities to aggregate sensitive assets (in prior cases, disinformation; now, offensive cyber capabilities) for undisclosed buyers.


    The timing and structure raise critical questions about intent. Why would convicted felons with zero documented cybersecurity expertise suddenly launch a venture requiring deep technical credibility and international regulatory compliance? Possible explanations range from financial motivation (exploit acquisition as money laundering) to operational expansion (acquiring capabilities for state or non-state customers unable to build their own pipelines).


    The federal contractor registration is the most telling detail. Debarment rules typically prevent convicted felons from accessing federal contracting. That Calvexa Group holds active contractor status despite Burkman and Wohl's convictions suggests either regulatory gaps or undisclosed legal clearance—both possibilities warrant closer scrutiny.


    For the security research community, IRIS C2 poses a direct threat to the ethics of vulnerability disclosure. The combination of high payouts, minimal vetting, and principals with no demonstrated ethical constraints creates a risk that exploits intended for legitimate research or defensive disclosure could be weaponized for criminal, political, or state-level operations. The lesson: researchers considering exploit sales should demand transparency not just about who is buying, but about how capabilities will be used—and should verify that buyers have legitimate, accountable operations.


    HackWire Editorial


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)