The Anatomy of a Zero-Day Charade: How Two Notorious Conspiracists Rebranded as Offensive Cyber Brokers

Executive Overview

A newly emerged cybersecurity venture promising multi-million-dollar bounties for zero-day software exploits has been identified as the latest front operation engineered by two of America’s most prolific political disinformation artists and convicted felons. Operating under the brand IRIS C2 and registered corporately as Calvexa Group LLC, the firm claims to procure high-tier cyber-weapons and phone-hacking capabilities for government clients. However, an extensive investigation reveals that the enterprise is led by Jacob Wohl, 28, and Jack Burkman, 60—a duo renowned for orchestrating fraudulent intelligence outfits, illicit financial schemes, and malicious voter suppression campaigns.

Promoting its activities via the X (formerly Twitter) handle @C2IRIS and its website irisc2[.]com, IRIS C2 claims to offer payouts ranging from $10,000 to $7 million for novel software vulnerabilities, targeting uncredentialed, young security researchers with raw technical talent. Despite public claims of operating active federal contracts and employing roughly 40 covert operatives, corporate filings indicate that Calvexa Group LLC holds no active direct federal contracts. The firm’s emergence highlights significant vulnerabilities in the offensive cybersecurity ecosystem, where the lucrative market for non-public software exploits intersects with unvetted defense contractors and predatory influence operations.

                    +---------------------------------------+
                    |           CALVEXA GROUP LLC           |
                    |    Registered Federal Contractor      |
                    | (No Direct Active Govt Contracts)     |
                    +-------------------+-------------------+
                                        |
                                        v
                    +-------------------+-------------------+
                    |               IRIS C2                 |
                    |    Public-Facing Cyber Platform       |
                    +-------------------+-------------------+
                                        |
              +-------------------------+-------------------------+
              |                                                   |
              v                                                   v
+---------------------------+                       +---------------------------+
|        JACOB WOHL         |                       |       JACK BURKMAN        |
| Age: 28 | "Jay Klein"     |                       | Age: 60 | "Bill Sanders"   |
| - Securities Fraud Conv.  |                       | - Managing Partner,      |
| - Telecommunications      |                       |   Burkman & Associates    |
|   Fraud Conviction        |                       | - Telecommunications      |
+---------------------------+                       |   Fraud Conviction        |
                                                    +---------------------------+

Detailed Chronology

The transition of Wohl and Burkman from disgraced financial promoters and far-right provocateurs into the rarefied world of defense-grade offensive cybersecurity represents the latest phase in a decade-long sequence of deceptive corporate ventures and adjudicated criminal conduct.

[2015-2017] -------------------------------------------------------->
• Wohl launches hedge funds as "Wohl of Wall Street"
• Arizona Corporation Commission files 14 counts of securities fraud

[2018-2020] -------------------------------------------------------->
• Duo creates fake intelligence entities (e.g., Surefire Intelligence)
• Fabricates smears against public figures (Mueller, Warren, Harris)
• Executes voter suppression robocalls targeting Black voters

[2022-2023] -------------------------------------------------------->
• Duo pleads guilty to felony telecommunications fraud in Ohio
• Ordered to pay $1M settlement in NY federal civil rights suit
• FCC levies record $5.1M penalty for TCPA violations

[2024] ------------------------------------------------------------->
• Launch of "LobbyMatic" under pseudonyms Jay Klein & Bill Sanders
• Recruited by Canadian crypto hacker ($300k retainer) for presidential pardon

[2025-Present] ----------------------------------------------------->
• Launch of IRIS C2 / Calvexa Group LLC
• Ohio voter suppression appeals rejected; probation imposed late 2025
• Public recruitment for $7M zero-day exploits begins

1. Financial Fraud and Early Schemes (2015–2019)

Jacob Wohl first gained public notoriety as a teenager, marketing himself as the "Wohl of Wall Street" during appearances on national financial news outlets. By 2017, the Arizona Corporation Commission formally charged Wohl and his investment funds with 14 counts of securities fraud, directing him to pay $35,000 in restitution. In 2019, Wohl’s financial dealings culminated in a criminal prosecution in California, where he pleaded guilty to four felony counts of selling unregistered securities and was sentenced to two years of probation.

2. Fabricated Intelligence Outfits and Disinformation (2018–2020)

Partnering with Washington, D.C. lobbyist Jack Burkman, Wohl established a sequence of fictitious investigative entities—most notably "Surefire Intelligence." The duo staged press conferences to disseminate fabricated sexual misconduct accusations against prominent public officials and political candidates, including former FBI Director Robert Mueller, Mayor Pete Buttigieg, Senator Elizabeth Warren, and then-Senator Kamala Harris. These operations relied on paid actors, falsified corporate records, and staged documentation.

3. Voter Suppression and Landmark Legal Penalties (2020–2023)

In the lead-up to the 2020 U.S. presidential election, the pair orchestrated a vast, illicit robocall operation that targeted tens of thousands of minority voters across battleground states, including Michigan and Ohio. The calls disseminated false information regarding mail-in voting to discourage participation.

  • State Criminal Charges: In 2022, both defendants pleaded guilty in Ohio to a felony charge of telecommunications fraud. After exhaustive appeals failed, they were sentenced in late 2025 to probation, fines, and community service.
  • Civil Rights Adjudication: In March 2023, a federal judge in New York ruled that their robocall campaign breached federal and state civil rights statutes, leading to a $1 million settlement agreement.
  • Regulatory Sanctions: In June 2023, the Federal Communications Commission (FCC) issued a historical $5.1 million fine against Wohl and Burkman—the largest penalty ever assessed under the Telephone Consumer Protection Act (TCPA).

4. Synthetic Lobbying and Pseudonymous Enterprises (2024)

In September 2024, investigative reports revealed that Burkman and Wohl had operated an artificial intelligence lobbying startup named LobbyMatic. The pair managed the operational affairs of the company behind false identities: Wohl adopted the pseudonym "Jay Klein," while Burkman posed as "Bill Sanders." Key staff members resigned after discovering that the executives directing the firm were convicted felons operating under fake names.

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

Concurrently, reports indicated that the pair received a $300,000 retainer from an indicted Canadian cryptocurrency actor accused by federal authorities of stealing $65 million from the decentralized finance platforms KyberSwap and Indexed Finance. The duo was retained to lobby for a executive pardon to evade federal prosecution.

5. The Pivot to Offensive Cybersecurity (2025–Present)

In January 2025, the X account @C2IRIS was created, marking the public inception of IRIS C2. The entity positioned itself as an offensive security firm based in McLean, Virginia, offering software exploit brokerage services and seeking to procure novel vulnerability chains from independent security researchers.


Supporting Context & Metrics

The Mechanics of the Zero-Day Exploitation Market

A "zero-day" refers to a security flaw in software that is unknown to the vendor and lacks a public patch. The commercial trade in zero-day exploits is divided between defense vendors selling exclusively to allied governments, legitimate security researchers participating in bug bounty programs, and illicit brokers serving cybercriminals.

IRIS C2 advertises payouts rivaling established defense contractors, offering up to $7 million for complete, stable exploit chains targeting mobile and desktop platforms.

Parameter IRIS C2 Advertised Scale Industry Baseline (Legitimate Vendors)
Minimum Bounties $10,000 $1,000 – $5,000
Maximum Bounties $7,000,000 $1,500,000 – $5,000,000
Target Scope iOS, Android, Windows, Media Decoders Specialized Government/Enterprise Systems
Recruitment Criteria Uncredentialed, "High IQ", No Degree Vetted Engineers, Proven Academic/Industry Track Record
Operational Transparency Anonymous Execs, Unverified Payouts Regulated Audits, Public Clearance Pathways
    [ Researcher Discovers Flaw ]
                 |
                 v
     [ Submits Exploit Primitive ]
                 |
                 v
   +-----------------------------------+
   |             IRIS C2               |
   | Claims: Weaponizes & Stabilizes   |
   | Reality: Unverified Operations    |
   +-----------------------------------+
                 |
                 v
    [ Claimed Sale to Govt Clients ]
    (No Active Direct Federal Contracts)

Corporate Shadow Footprint: Calvexa Group LLC

Corporate records link irisc2[.]com directly to Calvexa Group LLC, an entity registered as a federal contractor via the government portal G2Xchange.

       CALVEXA GROUP LLC CORPORATE STRUCTURE
       ======================================

       Registered Address:  Arlington, Virginia
       Occupant/Owner:      Jack Burkman (Founder, Burkman & Associates)
       Managing Executive:  Jacob Wohl (Operating under aliases)
       Domains Owned:       calvexagroup[.]com --> irisc2[.]com
       Federal Status:      Registered Contractor (Zero Direct Contracts)

Though registered to participate in federal procurement, public procurement databases show that neither Calvexa Group LLC nor IRIS C2 possesses active direct government contracts. Furthermore, while the company’s social media channels claim a workforce of 40 technical personnel, zero employees list the firm on professional networking platforms, a restriction Wohl asserts is necessary for "operational security."


Official Statements & Key Interrogations

When questioned regarding the true ownership and technical capabilities of IRIS C2, Jack Burkman distanced himself from daily oversight, deferring inquiries directly to Jacob Wohl.

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

In an interview, Jacob Wohl detailed his view of the company’s mission, his technical credentials, and the operational model behind IRIS C2.

On Technical Competence and Background

When pressed on his lack of formal computer science training or institutional background in information security, Wohl asserted:

"I know more about tech than anyone. My background has always been extremely technical, and I’ve always been deeply into tech. People know me as someone who is able to create spectacularly exquisite capabilities that would make your head spin."

On Exploit Acquisition and Pipeline

Wohl described the process by which IRIS C2 purports to acquire and refine raw vulnerability submissions from independent researchers:

"Let’s say someone finds a flaw in a media decoder on a phone. A lot of times what we receive is an exploit primitive, where the idea is there but the execution needs work. You need that exploit to be stable and reliable, and that’s what we do."

On Federal Contracting and Operations

Despite public procurement indexes demonstrating no active direct primary contract awards for Calvexa Group LLC, Wohl claimed that the entity actively serves government clients:

"Our focus shifted recently to selling phone-hacking services to the government… [We are] working on federal government contracts, [but] I am not at liberty to speak publicly about them."

Felons, Fraudsters Flog Offensive Cybersecurity Startup – Krebs on Security

Future Outlook

The entry of persistent bad actors into the sensitive market for zero-day vulnerabilities poses distinct risks to the cybersecurity ecosystem, government defense procurement, and independent researchers.

                   +---------------------------------------+
                   |     EMERGING RISKS & IMPLICATIONS     |
                   +-------------------+-------------------+
                                       |
         +-----------------------------+-----------------------------+
         |                             |                             |
         v                             v                             v
+------------------+          +------------------+          +------------------+
|   RESEARCHER     |          |  NATIONAL SEC.   |          |  REGULATORY &    |
|  EXPLOITATION    |          |    INTEGRITY     |          |   LAW ENFORCEMENT|
| Intellectual     |          | Vulnerability    |          | Contract fraud   |
| property theft & |          | leakage & fake   |          | risks & civil    |
| non-payment      |          | capabilities     |          | oversight        |
+------------------+          +------------------+          +------------------+

Vulnerability to Intellectual Property Theft

Independent vulnerability researchers—particularly young or uncredentialed engineers lured by promises of multi-million-dollar payouts—face extreme risks when dealing with entities operated by convicted fraudsters. Researchers submitting non-public "exploit primitives" to unvetted brokers risk having their intellectual property stolen, resold, or exposed without compensation or legal recourse.

Counterintelligence and Defense Supply Chain Risks

The brazen operational posture of IRIS C2 contrasts sharply with the rigorous vetting protocols mandatory within legitimate defense contracting. If a firm operating under fraudulent identities and false credentials attempts to broker zero-day exploits, it risks compromising critical security research, exposing raw exploits to hostile foreign actors, or corrupting valid procurement channels.

Impending Regulatory and Law Enforcement Oversight

Given Wohl and Burkman’s history of regulatory actions by the FCC, state attorneys general, and federal civil rights litigation, their involvement in dual-use offensive cyber technology is likely to attract heightened scrutiny from domestic regulatory bodies and law enforcement agencies:

  • Federal Procurement Oversight: Calvexa Group LLC’s status on government contractor portals may face administrative review or debarment if representations regarding corporate officers or existing contracts are found to be fraudulent.
  • Export Controls and ITAR: The broker of offensive exploits, particularly phone-hacking software and zero-day chains, is subject to strict export control laws, including the International Traffic in Arms Regulations (ITAR) and Commerce Department export rules. Operating an unauthorized broker network can lead to direct federal indictments.

The trajectory of IRIS C2 reflects a persistent pattern: the deployment of deceptive corporate structures to exploit emerging, high-value sectors. As security agencies and independent researchers scrutinize the firm’s claims, IRIS C2 stands as a stark warning regarding the integrity of the private zero-day exploitation market.

Leave a Reply

Your email address will not be published. Required fields are marked *