Exploit Ecosystem — Offensive Cybersecurity Startup Operated by Convicted Felons (N/A)
Publication date: July 8, 2026
Category: News
Introduction
Recent threat intelligence investigations have exposed a purported offensive cybersecurity firm named IRIS C2, which markets the acquisition of zero-day vulnerabilities and high-value exploitation capabilities with payouts reaching up to $7 million. However, the operation is run by public figures and federal convicts with a documented history of establishing shell companies and political disinformation campaigns. This analysis examines the security implications, the lack of verification controls within the vulnerability brokerage market, and the risks associated with fraudulent actors operating within the offensive security ecosystem.
What is IRIS C2 and the Exploit Brokerage Ecosystem? (General Analysis)
The vulnerability brokerage market is a highly opaque environment where independent researchers, academics, and intermediaries trade undisclosed software flaws (zero-days) to government entities and defense contractors.
IRIS C2 operates under the facade of a McLean, Virginia-based company, recruiting prospective engineers through promises of multimillion-dollar compensation for exploitation primitives and full chains targeting mobile and desktop platforms. However, corporate registry and government contracting verifications reveal that the entity is tied to Calvexa Group LLC, operated by Jack Burkman and Jacob Wohl, individuals with multiple prior convictions for securities fraud, telecommunications offenses, and civil rights violations linked to automated robocall campaigns.
- Risk Vector (Reasoned estimation): N/A (Does not apply to a specific software vulnerability, but rather to an institutional-level operational and social engineering risk).
- CWE Classification (Reasoned estimation): CWE-290 (Authentication Bypass by Spoofing - applied metaphorically to corporate credibility spoofing) and CWE-352 (Cross-Site Request Forgery - conceptualized in institutional trust manipulation).
How Does It Work? (Technical Analysis)
The modus operandi of such shell companies mimics the recruitment structures of legitimate defense contractors to attract technical talent and gather confidential intelligence regarding vulnerability research without possessing actual financial backing or awarded government contracts.
- Attraction and Recruitment Flow: Utilization of social media platforms (such as X/Twitter and LinkedIn) to disseminate appealing messaging regarding extreme financial compensation ($10,000 to $7 million), targeting junior engineers with high technical potential but limited due diligence experience.
- Operational Evasion and Pseudonyms: Operators employ false names (as previously documented in their failed AI-backed lobbying venture, LobbyMatic, where they used aliases like “Jay Klein” and “Bill Sanders”) and restrict public visibility of employees on professional networks under operational security (OPSEC) pretexts.
- Gathering of Exploitation Primitives: Approaching security researchers at regional conferences (such as OffensiveCon) to informally solicit preliminary findings and exploit primitives in browsers, media decoders, and mobile devices, under the promise of refining and commercializing them with government agencies.
Affected Systems / Environments
Since this is not a software vulnerability with an assigned CVE, the affected environments correspond to the offensive security research ecosystem and the institutional trust supply chain:
- Junior cybersecurity researchers and independent exploit developers exposed to intellectual property loss (undisclosed vulnerabilities).
- Physical security conference ecosystems and online communication channels where talent and proprietary technical information are solicited.
- Government contractors and agencies relying on intelligence supply chains and offensive cyber capabilities.
Mitigation and Detection
Remediation
- Rigorous Due Diligence: Organizations and independent researchers must independently verify corporate records, actual federal awards (via official portals such as SAM.gov or G2Exchange), and the identity of interlocutors before sharing any technical details or exploitation primitives.
- Sensitive Information Isolation: Never share functional proof-of-concept (PoC) code, reverse patches, or zero-day details with entities that lack accredited security certifications, publicly verifiable government contracts, and a transparent industry track record.
Detection
- Monitoring job openings and social media posts offering disproportionate compensation for vulnerability research without a legitimate, verifiable legal entity.
- Reputation analysis of domains linked to new offensive cybersecurity startups whose ownership records are hidden or tied to inactive LLCs.
“The offensive cybersecurity ecosystem is not a normal startup category; it operates at the intersection of national security, public trust, and regulatory frameworks. The absence of a strict verification mechanism for cyber capability claims exposes the community to fraud and intellectual property exfiltration risks.”
Wrapping Up
The case of IRIS C2 highlights the vulnerability of the security research market to fraudulent actors with criminal backgrounds who seek to capitalize on the secrecy and high profitability of the exploit sector. The lack of verification barriers in vulnerability acquisition not only threatens the intellectual assets of independent researchers but also undermines the integrity of defensive and offensive capabilities nationwide.
References
- KrebsOnSecurity. (2026). Felons, Fraudsters Flog Offensive Cybersecurity Startup. Retrieved from https://krebsonsecurity.com/?p=73834
