UNMASKING DPRK IT WORKERS
GhostHire
Fabricated histories are cheap to build.
Real footprints aren't.
Investigation scorecard
GhostHire surfaces risk signals to guide an investigation. It is not proof of fraud and not an accusation. Corroborate before acting.
Add a confirmed finding (things you verify off-tool: IPQS, HIBP, LinkedIn)
What the API tells you
GET https://api.github.com/users/<username>
Other signals
Repositories & orgs
One signal is not a verdict.
A young account with no fabricated history is not evidence of fraud; plenty of real developers are new to GitHub. Use this alongside other checks (PDF metadata, phone carrier, reverse image search, address validation). See the methodology for the full chain.
Drop a candidate's resume below. Everything is parsed in your browser, the file is never uploaded. We pull the document's hidden metadata and every contact artifact, then map each one to a check from the talk.
Roles DPRK IT workers commonly target (reference)
If the resume is for one of these, weight the other signals harder. Heavy concentration in remote dev and crypto/Web3.
- Full-stack / front-end / back-end web developer
- Blockchain / smart-contract / Solidity / Web3 developer
- Mobile developer (iOS / Android / React Native)
- AI / ML engineer
- DevOps / cloud / platform engineer
- UI / UX designer
- QA / test-automation engineer
- Game / Unity developer
Document metadata
Metadata signals
Extracted artifacts → what to do with them
The absence of a footprint is the signal, not the presence of a suspicious one.
A resume built in FlowCV or Word is not evidence of fraud. Real developers leave organic,
years-deep trails; fabricated personas leave thin, recent, inconsistent ones. Corroborate before acting.