HackMyIP
← Back to News
2026-07-08 KrebsOnSecurity

IRIS C2: Felons Behind Zero-Day Exploit Marketplace Exposed

Zero-DayThreat IntelVulnerability

The offensive cybersecurity startup IRIS C2, which publicly markets itself as a buyer of zero-day exploits offering payouts of up to $7 million, is operated by convicted felons and far-right conspiracy theorists Jack Burkman and Jacob Wohl, according to a KrebsOnSecurity investigation. The X/Twitter account @C2IRIS, created in January 2025, has amassed more than 4,000 followers by posting about security vulnerabilities, AI tools, and software exploits while dangling lucrative payouts to attract what its pinned post calls "junior engineers with raw talent/extremely high IQ" — regardless of credentials or experience.

The company is registered federally as Calvexa Group LLC in Virginia, with its g2exchange.com profile and the calvexagroup[.]com domain both forwarding visitors directly to irisc2[.]com. The incorporation address traces to Burkman & Associates, Burkman's lobbying firm in Arlington, VA. IRIS C2 claims to acquire "zero-day exploits, individual primitives, partial chains, and full capabilities across all major platforms," with payouts scaled from $10,000 to $7 million depending on target reliability and operational value. Yet federal contractor records indicate Calvexa Group holds no active government contracts, raising questions about how the firm monetizes any acquired offensive capabilities.

Burkman, 60, and Wohl, 28, have a documented history of running fake intelligence companies to spread fabricated claims targeting public figures — including bogus sexual assault allegations against then-FBI Director Robert Mueller and Democratic politicians Pete Buttigieg, Elizabeth Warren, and Kamala Harris, followed by prosecution in the wake of the 2020 election. Their latest venture follows the same playbook: a polished public persona masking a dubious operation. Security researchers and exploit developers considering engagement with such firms should verify corporate domains using a WHOIS lookup and inspect site certificates via an SSL/TLS checker before sharing vulnerability research or signing any contracts, since weaponized exploit disclosures handed to fraudulent brokers can be leaked, resold, or weaponized against the original reporter.

The case underscores a structural weakness in the offensive cyber market: the absence of rigorous vetting for buyers of zero-day capabilities. Anyone evaluating their own digital exposure in light of these trends should also run a privacy checkup to identify what an opportunistic actor — or a fraudulent exploit broker — could already discover about them. As law enforcement scrutiny of Burkman and Wohl continues, researchers are advised to treat unsolicited offers from little-known exploit acquisition firms with extreme skepticism.

Source: KrebsOnSecurity →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →