Shadow Operations and Silicon Schemes: The True Identity Behind "IRIS C2" and Its Notorious Founders

Main page Cyber Security & Privacy Shadow Operations and Silicon Schemes:…
From ZizzMedia, the free news encyclopedia
Shadow Operations and Silicon Schemes: The True Identity Behind "IRIS C2" and Its Notorious Founders
Shadow Operations and Silicon Schemes: The True Identity Behind "IRIS C2" and Its Notorious Founders
Published: 25 August 2026
Author: Laily UPN
Category: Cyber Security & Privacy
Read time: 11 min read
Words: 2,045

Executive Overview

In the sprawling, often murky ecosystem of the offensive cybersecurity industry, recruiting talent requires a delicate balance of discretion, financial incentive, and operational mystique. However, a newly emerged startup calling itself IRIS C2 has shattered standard conventions, thrusting itself into the public spotlight with staggering multimillion-dollar offers for unpatched software vulnerabilities, colloquially known as "zero-days." Operating heavily via social media and boasting an active recruitment campaign, IRIS C2 claims to be a premier broker of advanced exploit chains and offensive capabilities for major platforms, dangling up to $7 million for elite software exploits.

Yet, behind the slick web presence, the bold recruitment pitches, and the viral social media threads lies a startling reality. An investigative deep-dive reveals that IRIS C2 is not spearheaded by seasoned cyber-warfare veterans or Silicon Valley software architects. Instead, the venture is run by a pair of infamous far-right conspiracy theorists, grifters, and convicted felons: Jacob Wohl and Jack Burkman.

Best known for a decade-long trail of elaborate political hoaxes, fake intelligence front companies, voter suppression robocall operations, and multi-million-dollar regulatory fines, Wohl and Burkman have quietly pivoted their administrative machinery toward the high-stakes, lucrative world of software exploitation. Operating under the corporate umbrella of a Virginia-registered entity called Calvexa Group LLC, the duo is leveraging pseudonyms, stealth recruitment tactics, and exaggerated technical claims to acquire preliminary security vulnerabilities.

This exposé explores the emergence of IRIS C2, tracing the tangled web of its founders’ past criminal enterprises, evaluating the credibility of their claims within the offensive security market, and examining the potential national security implications of convicted fraudsters attempting to infiltrate the government contracting and exploit brokerage supply chain.


Detailed Chronology of the IRIS C2 Venture

The public genesis of IRIS C2 can be traced back to January 2025, when a newly created account on X (formerly Twitter) under the handle @C2IRIS (IRIS C2) began broadcasting frequent commentary regarding artificial intelligence, software exploits, and vulnerability research. Within a matter of months, the account rapidly amassed upwards of 4,000 followers, fueled by aggressive posts, pinned recruitment manifestos, and bold assertions regarding the firm’s financial backing.

The corporate strategy advertised by IRIS C2 relies on recruiting raw, unconventional talent. A pinned manifesto on their social media profile reads:

"Our business model is this: Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience."

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

Directing traffic to its official domain, irisc2[.]com, the startup invites prospective applicants to submit their resumes for various open positions. Simultaneously, the portal advertises an aggressive acquisition schedule for zero-day vulnerabilities, individual exploit primitives, partial chains, and end-to-end capabilities spanning all major operating systems and consumer hardware platforms. Depending on the operational value, target relevance, and reliability of the code, IRIS C2 claims to offer payouts ranging anywhere from $10,000 to an eye-watering $7 million.

Publicly accessible federal procurement and business registry records maintained by portals such as g2exchange.com trace the infrastructure of irisc2[.]com directly back to a Virginia corporate entity known as Calvexa Group LLC. Network routing and redirection mechanisms on the corporate website—calvexagroup[.]com—seamlessly forward web traffic directly to the IRIS C2 exploit acquisition portal. While G2Exchange confirms that Calvexa Group LLC is officially registered as a federal contractor, government records show no evidence of active, direct federal prime contracts awarded to the firm.

Physical tracking of the corporate incorporation records leads investigators to an address in Arlington, Virginia. Property and public records confirm the location is occupied by 60-year-old Jack Burkman, a fixture of Washington, D.C. political consulting and the founder of the lobbying firm Burkman & Associates. When contacted regarding the operations of IRIS C2, Burkman deflected questions, steering inquiries toward his long-standing business associate, 28-year-old Jacob Wohl.


Supporting Context & Metrics: A History of Fraud and Fabrication

To understand the severe skepticism directed at IRIS C2 by veteran information security professionals, one must examine the staggering rap sheet and corporate history of its principals. Jacob Wohl and Jack Burkman are not recognized entities in the computer science community; rather, they are infamous figures in American political fringe circles, having built a multi-year portfolio defined by systematic disinformation campaigns, civil liabilities, and criminal convictions.

The Political Hoaxes and Defamation Lawsuits

Throughout the late 2010s and early 2020s, Wohl and Burkman routinely orchestrated elaborate press conferences and media stunts designed to smear high-profile public figures. Their playbook typically involved the creation of phantom intelligence front companies to launder false claims:

  • Fabricated Scandals: The duo pushed fabricated sexual assault allegations against then-FBI Director Robert Mueller and Democratic presidential candidate Pete Buttigieg. They also held theatrical press conferences in 2019 alleging fabricated extramarital affairs by Senator Elizabeth Warren and then-candidate Kamala Harris.
  • Civil Rights Violations: In March 2023, a federal judge in a New York civil rights case ruled that Wohl and Burkman had deliberately violated both state and federal civil rights protections by deploying targeted harassment campaigns. The pair ultimately agreed to a crushing $1 million civil settlement.

Voter Suppression Robocalls and Federal Penalties

The aftermath of the 2020 U.S. presidential election marked a major escalation in the legal consequences faced by Wohl and Burkman. The duo orchestrated a massive robocall campaign across multiple battleground states, inundating residents with false, alarmist claims regarding mail-in ballots designed to suppress voter turnout.

  • Felony Indictments: A grand jury in Cleveland, Ohio, indicted Wohl and Burkman on 15 felony counts for orchestrating a targeted robocall scheme explicitly aimed at suppressing the Black vote in Detroit. After exhausting various appeals to dismiss the charges, the pair pleaded guilty in late 2022 to a single felony count of telecommunications fraud. Their sentence included steep financial restitution, strict probation, and court-mandated community service.
  • Record FCC Sanctions: In June 2023, the Federal Communications Commission (FCC) levied a historic $5.1 million administrative penalty against Wohl and Burkman for their illegal robocall campaigns—marking, at the time, the largest financial forfeiture ever sought by the agency under the Telephone Consumer Protection Act (TCPA).

Financial Fraud and the "Wohl of Wall Street"

Jacob Wohl’s history of financial regulatory violations predates his political stunts. Entering the public eye as a teenager, Wohl boasted of managing investment firms and cultivated the moniker "Wohl of Wall Street" after a 2015 appearance on Fox News.

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security
  • Securities Fraud: In 2017, the Arizona Corporation Commission charged Wohl and his associated investment funds with 14 distinct counts of securities fraud, mandating $35,000 in restitution.
  • California Guilty Plea: In 2019, Wohl pleaded guilty in a California court to four felony counts of selling unregistered securities, receiving a two-year probation sentence.

The Precedent of "LobbyMatic" and Pseudonyms

The transition from political consulting to technical startups follows a playbook already executed by Wohl and Burkman just months before launching IRIS C2. In late 2024, an investigative report by Politico revealed that the pair had launched an AI-powered political lobbying platform dubbed LobbyMatic. To obscure their toxic public reputations, Wohl and Burkman operated the firm entirely under pseudonyms: Wohl adopted the alias "Jay Klein," while Burkman operated as "Bill Sanders."

When internal employees eventually discovered the true identities of their employers, multiple staff members immediately resigned in protest, while others remained entirely oblivious until after their departure. This strategy of adopting false identities and compartmentalizing workforce awareness appears to have carried over directly into the operational security (OpSec) protocols of IRIS C2.

Cryptocurrency Ties and International Fugitives

Further complicating the backdrop of the founders’ recent activities, investigative reporting published by journalist Molly White in March 2025 revealed that Wohl and Burkman accepted a lucrative $300,000 financial retainer from a Canadian cryptocurrency figure. The individual in question is currently an international fugitive wanted by United States federal law enforcement and global regulatory bodies for allegedly orchestrating complex hacking and laundering schemes that drained over $65 million from decentralized finance protocols, including KyberSwap and Indexed Finance. According to public disclosures, the duo was hired to lobby for a presidential pardon to shield the accused hacker from prosecution.


Official Statements and Industry Reception

The offensive cybersecurity market is traditionally characterized by extreme discretion. While defense contractors, intelligence agencies, and specialized brokers routinely acquire zero-day vulnerabilities, they operate within heavily vetted, discreet networks. The loud, social-media-driven marketing approach adopted by IRIS C2 stands in stark contrast to industry norms, immediately raising red flags among veteran security researchers.

The KrebsOnSecurity Interview

In an exclusive interview with investigative journalist Brian Krebs, Jacob Wohl attempted to downplay the involvement of Jack Burkman, asserting that Burkman maintains no active role in the day-to-day management of IRIS C2. According to Wohl, the enterprise initially launched as a standard penetration testing consultancy before pivoting its operational focus toward selling specialized mobile device exploitation and "phone-hacking" capabilities directly to federal government agencies.

When pressed for specifics regarding active federal procurement contracts or institutional clients, Wohl repeatedly cited government confidentiality, claiming he was "not at liberty to speak publicly" about classified or sensitive engagements.

Wohl openly admitted that he possesses no formal academic training, university degrees, or professional certifications in computer science, software engineering, or information security. Instead, he claimed his expertise is entirely self-taught, offering a characteristically grandiose self-assessment:

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

"I know more about tech than anyone. My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."

Refining Exploit Primitives

Discussing the technical mechanics of IRIS C2’s acquisitions, Wohl described a pipeline where external independent researchers pitch raw vulnerability findings to the firm. He noted that initial submissions are rarely complete, production-ready exploit chains:

"Let’s say someone finds a flaw in a media decoder on a phone. A lot of times what we receive is an exploit primitive, where the idea is there but the execution needs work. You need that exploit to be stable and reliable, and that’s what we do."

Despite claiming a workforce of approximately 40 employees, Wohl explained that internal personnel are strictly prohibited from listing their employment with IRIS C2 on professional networking platforms like LinkedIn, citing operational security. This secrecy mirrors the pseudonymous management style utilized during their defunct LobbyMatic venture.

Industry analysts point out that if IRIS C2 does employ genuine technical talent or junior exploit developers, those individuals may be entirely unaware of the criminal records, civil fraud judgments, and history of identity deception belonging to the company’s true leadership.


Future Outlook and National Security Implications

The emergence of IRIS C2 introduces a bizarre and concerning intersection between fringe political operatives, white-collar criminality, and the shadowy global market for offensive cyber weapons. As zero-day brokers face increasing regulatory scrutiny worldwide, the introduction of unregistered, highly volatile entities operated by convicted felons poses several distinct risks:

  1. Supply Chain Compromise and Counter-Intelligence Vulnerabilities: Federal agencies and private defense contractors maintain rigorous vetting processes to prevent malicious actors from inserting compromised or backdoored exploit code into sovereign defensive arsenals. The involvement of individuals with extensive records of financial fraud, foreign financial entanglements with international cyber fugitives, and deliberate deception raises profound counter-intelligence concerns.
  2. Talent Exploitation and Labor Risks: Young, ambitious vulnerability researchers—lured in by promises of million-dollar payouts and unconventional hiring criteria—risk legal, professional, and ethical jeopardy by entering into commercial agreements with corporate entities controlled by individuals legally barred from various commercial and telecommunications activities.
  3. Regulatory Crackdowns: Given the massive regulatory penalties already levied against Wohl and Burkman by agencies like the FCC, federal oversight bodies are likely to cast a wary eye on Calvexa Group LLC and its associated digital infrastructure, potentially triggering formal investigations into their federal contractor registrations.

Ultimately, whether IRIS C2 is a genuine attempt to carve out a foothold in the competitive exploit brokerage market or merely another iteration of the elaborate front-company grifts that have defined Wohl and Burkman’s careers, the venture underscores the chaotic, unregulated fringes of the modern cybersecurity landscape. As security researchers and federal watchdogs monitor developments closely, the saga of IRIS C2 serves as a stark reminder that in the digital age, advanced technical ambition can easily mask a foundation built entirely on deception.

Related News

Leave a Reply / Join Discussion

Your email address will not be published. Required fields are marked with *