All stories

IRIS C2 offers seven million dollars for high value zero day exploits

A new offensive cybersecurity startup called IRIS C2 is attempting to acquire high-value zero-day exploits with payouts reaching $7 million. The company is operated by individuals with histories of fraud and political controversy rather than established technical credentials. Defenders should monitor for unusual outreach from entities claiming to broker mobile or platform-wide capabilities.

Summary

IRIS C2, a startup claiming to be based in McLean, Virginia, has entered the offensive security market with an aggressive recruitment strategy targeting vulnerability researchers. The company is publicly advertising payouts ranging from $10,000 to $7 million for zero-day exploits, individual primitives, and full capabilities across all major platforms.

While the company presents itself as a professional entity specializing in high-end offensive capabilities, its leadership consists of individuals with extensive criminal records involving fraud and political disinformation. The firm operates under Calvexa Group LLC, a registered federal contractor that does not currently appear to hold direct government contracts.

The IRIS C2 Business Model

The startup's recruitment strategy relies heavily on social media presence, specifically an X/Twitter account (@C2IRIS) that has gained over 4,000 followers since January 2025. The company targets "junior engineers with raw talent" and high IQs, explicitly stating they do not require formal college degrees or industry experience.

According to Jacob Wohl, a managing partner at the firm, IRIS C2 has pivoted from penetration testing toward selling phone-hacking services to government entities. Wohl claims the company currently employs approximately 40 people, though he notes that employees are prohibited from listing their roles on professional networking sites like LinkedIn for operational security reasons.

The technical focus of the firm involves taking "exploit primitives"-incomplete or unstable vulnerabilities-and developing them into reliable, stable exploits. This includes targeting flaws in components such as mobile media decoders to achieve full device compromise.

Leadership and Background

The leadership behind IRIS C2 consists of Jack Burkman and Jacob Wohl, both of whom have documented histories involving legal issues related to fraud and disinformation.

  • Jack Burkman: The founder of the lobbying firm Burkman & Associates. His registered business address in Arlington, Va., is currently occupied by his lobbying firm.
  • Jacob Wohl: A former hedge fund operator who has faced multiple charges, including securities fraud and telecommunications fraud. In 2019, Wohl pleaded guilty to four felony counts of selling unregistered securities.

The pair previously operated a company called LobbyMatic using pseudonyms-"Jay Klein" and "Bill Sanders"-to hide their identities from employees and the public. Their history includes significant legal penalties, such as a $5.1 million fine imposed by the FCC for robocall campaigns.

Why this matters for defenders

The emergence of brazen, highly public brokers for zero-day vulnerabilities changes the landscape of exploit acquisition. Unlike traditional, more discreet government contractors, IRIS C2 uses high-profile social media presence to solicit research.

For security researchers and developers, this represents a potential new avenue for selling findings, but it also introduces risks regarding the legitimacy of the buyers. The lack of transparency regarding their actual government clients or specific technical capabilities suggests a high degree of opacity in their operations.

Defenders should be aware that companies like this focus on "full capabilities," which often implies targeting mobile operating systems and core media processing components to gain unauthorized access.

Sources

  1. https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -