Two convicted fraudsters are operating IRIS C2 under a government contractor front to openly solicit high-payout zero-day vulnerabilities from researchers. The operation markets exclusive rights to novel software exploits with payouts reaching millions of dollars.