Anatomy of an Operation: How Far-Right Provocateurs Jacob Wohl and Jack Burkman Reemerged in the High-Stakes World of Zero-Day Exploits

Share
Anatomy of an Operation: How Far-Right Provocateurs Jacob Wohl and Jack Burkman Reemerged in the High-Stakes World of Zero-Day Exploits

Executive Overview

The shadowy ecosystem of offensive cybersecurity and vulnerability acquisition has long attracted a colorful mix of elite academics, mercenaries, venture capitalists, and cybercriminals. Operating in the twilight between legitimate defense contractors and illicit exploitation markets, these brokers deal in "zero-days"—unknown software flaws that can grant remote, silent access to millions of devices.

Yet, even within an industry historically defined by discretion and operational opacity, a new player has emerged with an audaciously public posture: IRIS C2.

Promising million-dollar payouts for high-value software exploits, the Virginia-based startup has aggressively courted talent on social media platforms like X (formerly Twitter) and LinkedIn. Claiming to recruit raw technical prodigies regardless of academic credentials, IRIS C2 dangles financial incentives ranging from $10,000 to $7 million for software primitives, partial exploit chains, and full mobile capabilities.

However, an investigative look behind the corporate facade reveals a startling reality. Far from being a conventional boutique contractor or an elite red-team shop, IRIS C2 is operated by a pair of infamous, far-right political operatives and convicted felons: Jack Burkman and Jacob Wohl.

Behind the pseudonyms, the polished corporate websites, and the brazen recruitment pitches lie the same individuals notorious for orchestrating fabricated sexual assault smears against political figures, launching racially targeted election-interference robocalls, and running defunct artificial intelligence lobbying fronts under fake names. Now, the duo has pivoted their chaotic brand of political theater into the highly sensitive, highly lucrative domain of offensive cyber operations.


Detailed Chronology: From Electoral Subversion to Zero-Day Brokering

The Genesis of IRIS C2

In January 2025, an account operating under the handle @C2IRIS appeared on X, identifying itself as IRIS C2, a McLean, Virginia-based firm specializing in offensive cybersecurity capabilities. Over the span of months, the account rapidly accumulated thousands of followers by posting technical commentary on software vulnerabilities, artificial intelligence, and operating system exploits.

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

Pinned to the top of the account’s profile is a mission statement outlining its aggressive recruitment strategy:

"Our business model is this: Attract the very best vulnerability researchers and exploit developers in the world to join our company. This mostly revolves around junior engineers with raw talent/extremely high IQ. We don’t care if they have a college degree/industry experience."

Linked directly to a domain—irisc2[.]com—the enterprise advertised multiple engineering vacancies, boasting on professional networking sites about an overwhelming influx of applicants. The website outlines a tiered bounty schedule, targeting zero-day exploits across all major platforms with valuations reaching up to $7 million depending on target stability and strategic value.

Unmasking Calvexa Group LLC

Public government contracting records maintained by portals such as g2exchange.com trace the operational entity behind irisc2[.]com to a Virginia-registered business called Calvexa Group LLC. Corporate registration data directs inquiries to an associated web portal (calvexagroup[.]com), which transparently redirects visitors straight to the IRIS C2 main page. While federal registries show Calvexa Group LLC holds an active status as a registered federal contractor, historical logs indicate it has secured no substantive direct government procurement contracts.

A physical audit of the Arlington, Virginia, corporate address listed in Calvexa Group’s incorporation documents leads directly to property occupied by Jack Burkman, the 60-year-old managing partner of Burkman & Associates. When approached for comment regarding the enterprise, Burkman deflected and pointed investigators toward his longtime, younger business associate, Jacob Wohl.

A History of Political Smears and Fraud

The partnership between Burkman and Wohl is well-documented in American political and legal history, characterized by successive waves of fraudulent schemes, fabricated intelligence operations, and coordinated disinformation campaigns.

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security
  • 2015–2017 (Securities Fraud): Beginning his career as a teenager, Wohl gained media attention as a self-styled wunderkind dubbed the "Wohl of Wall Street." In 2017, the Arizona Corporation Commission charged Wohl and his investment funds with multiple counts of securities fraud, ordering substantial restitution. This culminated in 2019 when Wohl pleaded guilty in California to four felony counts of selling unregistered securities, receiving two years of probation.
  • 2018–2020 (Political Disinformation Campaigns): Wohl and Burkman leveraged fake intelligence firms to manufacture elaborate smears against public figures. These included fabricated sexual assault allegations targeting then-FBI Director Robert Mueller and presidential candidate Pete Buttigieg, alongside false press conferences alleging personal indiscretions by prominent Democratic lawmakers such as Senator Elizabeth Warren and then-Senator Kamala Harris.
  • 2020 (Voter Suppression Robocalls): In the shadow of the 2020 U.S. presidential election, the duo deployed thousands of racially targeted robocalls across key swing states, disseminating false claims designed to discourage mail-in voting. Subsequent criminal investigations led to indictments in multiple jurisdictions, most notably a 15-count felony indictment in Cleveland, Ohio, targeting a voter-suppression scheme aimed at the Black community in Detroit. After unsuccessful legal challenges to dismiss the charges, both men were sentenced to probation.
  • 2021–2023 (Civil Penalties and Federal Fines): In 2022, Wohl and Burkman pleaded guilty to a single felony count of telecommunications fraud in Ohio. By March 2023, a New York federal civil judge ruled that their actions violated state and federal civil rights protections, resulting in a $1 million settlement agreement. Shortly thereafter, in June 2023, the Federal Communications Commission (FCC) levied a record-breaking $5.1 million fine against the pair—the largest financial penalty ever sought under the Telephone Consumer Protection Act.
  • 2024 (LobbyMatic Pseudonyms): In late 2024, investigative reporting by Politico revealed that Wohl and Burkman were operating a defunct artificial intelligence lobbying platform called LobbyMatic. To obscure their involvement from prospective corporate clients and workers, Wohl adopted the alias "Jay Klein," while Burkman operated under the moniker "Bill Sanders." Multiple employees resigned upon discovering the true identities of their leadership.
  • Early 2025 (The Crypto Pardon Brokerage): Further spotlighting their financial entanglements, public disclosures highlighted by journalist Molly White in March revealed that Wohl and Burkman accepted a $300,000 retainer from a Canadian cryptocurrency fugitive. Wanted internationally for allegedly orchestrating a $65 million hacking scheme against decentralized finance platforms KyberSwap and Indexed Finance, the fugitive reportedly hired the pair to lobby for a presidential pardon.

Supporting Context & Metrics

The market for previously unknown software vulnerabilities—commonly referred to as zero-days—operates within a complex gray area. Legitimate bug bounty programs run by corporate technology giants routinely pay researchers thousands or tens of thousands of dollars to patch vulnerabilities. Simultaneously, private brokers, defense contractors, and specialized intelligence intermediaries acquire exclusive capabilities to resell offensive access to government agencies and law enforcement bodies.

+-------------------------------------------------------------------------+
|                    THE ZERO-DAY BROKERAGE ECOSYSTEM                     |
+-------------------------------------------------------------------------+
|                                                                         |
|  [Independent Researchers] ---> [Private Brokers / Startups]            |
|                                       |                                 |
|                                       v                                 |
|                                 (IRIS C2 / Calvexa)                     |
|                                       |                                 |
|              +------------------------+------------------------+      |
|              |                                                 |      |
|              v                                                 v      |
|    [Government Clients]                               [Exploit R&D]     |
|   (Offensive Operations)                           (Primitive Stacking)|
+-------------------------------------------------------------------------+

While established contractors within the defense ecosystem engage in similar recruitment channels with a high degree of discretion, IRIS C2’s entry into the space represents a stark departure in protocol.

Scale and Financial Exposure

  • Follower Growth: The @C2IRIS X account expanded its reach to over 4,000 followers within weeks of its January 2025 launch.
  • Bounty Tiering: Publicized acquisition budgets scale dynamically from baseline findings ($10,000) up to enterprise-level payouts ($7 million) contingent upon operational reliability.
  • Legal and Regulatory Liabilities: Combined state and federal penalties resulting from prior operations—including the FCC’s $5.1 million fine and New York’s $1 million civil settlement—demonstrate a persistent track record of regulatory sanctions running parallel to their new corporate ventures.

Official Statements & Interviews

In an interview addressing the launch and operations of IRIS C2, Jacob Wohl maintained that Jack Burkman exercises no day-to-day oversight over the cybersecurity venture. According to Wohl, the enterprise initially focused on traditional penetration testing before transitioning its primary strategic focus toward supplying specialized remote access and phone-hacking capabilities to federal government customers.

When questioned regarding specific federal contracts, Wohl declined to provide verifiable details, asserting that operational security restrictions prevented him from discussing active agreements publicly.

Admitting that he lacks formal academic credentials, computer science degrees, or traditional institutional training in information security, Wohl claimed his technical acumen is entirely self-taught:

"I know more about tech than anyone," Wohl stated during the interview. "My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

Detailing the mechanics of how IRIS C2 processes incoming vulnerability submissions, Wohl explained that raw research provided by freelance developers frequently requires significant post-processing to meet operational standards:

"Let’s say someone finds a flaw in a media decoder on a phone," Wohl explained. "A lot of times what we receive is an exploit primitive, where the idea is there but the [execution] needs work. You need that exploit to be stable and reliable, and that’s what we do."

Wohl further claimed that IRIS C2 employs an internal workforce of approximately 40 individuals. However, he noted that none of these purported employees are permitted to publicly display their employment status on professional networks like LinkedIn, attributing the restriction to standard operational security protocols.


Future Outlook

The pivot of political provocateurs into the high-stakes, highly regulated domain of offensive cyber capabilities raises serious questions regarding the vetting processes governing federal contracting networks and commercial vulnerability brokers.

While IRIS C2 markets itself as an elite broker capable of competing with established commercial exploit acquisitions firms, its leadership’s extensive criminal history, reliance on pseudonyms, and legacy of fraudulent business fronts suggest a enterprise built more on high-risk public posturing than sustainable technological innovation.

As cybersecurity researchers, federal investigators, and industry watchers continue to monitor the activities of Calvexa Group LLC and its principals, the intersection of political fringe actors and offensive cyber proliferation remains a volatile frontier. Whether IRIS C2 can successfully deliver on its multi-million-dollar bounty promises—or whether it will collapse under the weight of regulatory scrutiny, legal liabilities, and the exposure of its operators—remains to be seen.

Did you find this story helpful?

Share it with your friends and colleagues on social media.

Share

Leave a Comment

Your email address will not be published. Required fields are marked *