IRIS C2: The Offensive Exploit Company with a Criminal Past
Vulnerabilities

Illustrative image generated with AI

IRIS C2: The Offensive Exploit Company with a Criminal Past

IRIS C2, led by fraudsters Burkman and Wohl, targets zero-day researchers. Discover why selling exploits to them poses severe legal and security risks.

Text generated by artificial intelligence, published without human review. AI transparency

Introduction

In the offensive security landscape, IRIS C2 (@C2IRIS) has recently emerged, a company that claims to acquire zero‑day vulnerabilities and exploit chains for up to $7 million per submission and to provide hacking services (mainly phone hacking) to the U.S. government. Behind the facade, however, lie Jack Burkman and Jacob Wohl, two names notoriously known for fraud, disinformation campaigns, and civil rights violations. The operation, conducted through Calvexa Group LLC, raises serious alarms for the entire cybersecurity ecosystem.

Technical Analysis

The technical foundations of IRIS C2 are weak. Neither Burkman (60) nor Wohl (28) possess credentials or documented experience in vulnerability research: Wohl himself has claimed to be self‑taught. Their legal history instead speaks of wire fraud (a robocall system aimed at suppressing African‑American votes, 2020–2025), FCC sanctions of $5.1 million, civil fines exceeding one million, financial scams, and false sexual allegations against public figures.

Calvexa Group LLC, registered as a federal contractor but lacking active government contracts, has its legal address at a location traceable to lobbyist Burkman. Operationally, IRIS C2 aggressively targets X and LinkedIn to hook researchers, sometimes even during international conferences, touting non‑existent government contracts. The complete absence of a credible technical‑legal framework suggests that any acquired exploits could be used for extortion, disinformation operations, or resale to unauthorized parties, consistent with the founders’ historical modus operandi.

Impact

The entry of figures with such a track record into the zero‑day market creates multi‑level risks:

  • Direct threat to users and businesses: critical vulnerabilities (browsers, operating systems, mobile devices) could be used in indiscriminate attacks.
  • Erosion of trust in the legal market: the presence of fraudulent intermediaries harms the reputation of bug bounty programs and regulated trading, discouraging researchers from responsible disclosure.
  • Legal risk for researchers: selling exploits to individuals with such a serious criminal record could constitute complicity in illegal activities, with criminal and civil repercussions for the provider themselves.

Mitigation

To defend against similar operations, it is essential to perform rigorous due diligence on every potential buyer:

  • Verify the actual existence of public contracts (e.g., USAspending.gov) and the founders’ reputation.
  • Check criminal records, corporate registrations, and references in the cybersecurity industry.
  • In this specific case, avoid any collaboration or code transfer to IRIS C2 and Calvexa Group.

Researchers contacted by these entities should:

  • Not respond to communications.
  • Immediately report the incident to national CERTs, law enforcement, or their organization’s leadership.
  • Also inform conference organizers where such individuals might attempt approaches.

Government agencies should also carefully map their offensive supply chain, excluding unaccredited sub‑contractors with criminal profiles.

FAQ

1. Does IRIS C2 really have contracts with the U.S. government?
No. Although Calvexa Group LLC is registered as a federal contractor, there is no evidence of active public contracts. The legal address traces back to Jack Burkman, but the company has never demonstrated operational links with U.S. agencies.

2. What are the concrete risks of selling an exploit to IRIS C2?
The danger is threefold: (a) the exploits could be used for extortion, information manipulation, or direct attacks; (b) the vulnerability could be resold without any control; (c) the researcher could be held complicit in any crimes committed with that exploit, with serious legal consequences.

3. How can I recognize a suspicious approach from this company?
IRIS C2 mainly contacts via X (@C2IRIS), LinkedIn, or through the irisc2.com website, promising payments of up to $7 million and displaying aggressive tones. The absence of demonstrable technical skills, the registration under Calvexa Group, and the well‑known criminal record of the founders are clear warning signs. Any communication should be handled with extreme caution and reported to authorities.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicsIRIS C2Calvexa Groupzero-day vulnerabilitiesexploit companyJack BurkmanJacob Wohlcybersecurity risks
Back to home