Romance scams get a new twist: fake girls invading DMs to promote OnlyFans accounts
Phishers are finding OnlyFans subscription upsells profitable enough to fuel massive bot campaigns.

Image by Kaspars Grinvalds | Shutterstock
- AI-powered fake-girl bots target gamers and social media users, steering them toward OnlyFans subscriptions or scams.
- Bots build trust through flattery, move chats to Discord, and use recycled images and scripted messages at scale.
- Some campaigns promote real accounts through deceptive operators; others impersonate creators, steal money, or hijack user accounts.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Fake-girl AI bots are spilling beyond OnlyFans, actively hunting for potential subscribers across TikTok, Discord, and even League of Legends. Phishers are repurposing their playbook to upsell both real and fake explicit content.
The lines are blurring between phishing and OnlyFans content promotion. Security researchers warn of scammer-controlled AI chatbots that target gamers and social media users.
No malicious links, attachments, payment requests, or fake login pages are presented to the victims. Just a simple link to the OnlyFans account.
The bot promises to “get dirty” and send “some actual nudes,” and promotes it as an exclusive, limited-time offer.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Girl bots are spreading to gaming chats
Malwarebytes reports that League of Legends (LoL) gamers are receiving friend requests from their opponents after each match. An automated bot impersonates a fake girl.
The initial rapport-building borrows from a tried-and-tested phishing tactic: the romance script.
The new “friend” compliments the target’s game style, writes other flattery, and invites them to Discord, where the conversation turns increasingly flirtatious. The bot shares a steady stream of suggestive photos, only stopping short of explicit content.
Already reported by multiple other LoL players, this scam doesn’t even promote obviously fake accounts.
A Malwarebytes employee was invited by one of the bots to subscribe to an OnlyFans account with nearly 20,000 likes. The account charges $3.75 a month for a subscription, claiming an 85% discount from the regular $25 monthly price.
The reverse image search revealed that the same photo was recycled on other unrelated websites and a YouTube video, and other users reported receiving identical images, suggesting an automated, large-scale campaign rather than activity by a single individual.
“That doesn’t make it harmless. Even when the underlying OnlyFans account is real, the conversations are very likely run by paid chat operators or scripted/AI-powered systems working from a shared script and a reused media library,” Malwarebytes warns.
Former OnlyFans “chatters” described the business model, in which agencies assign staff and bots to respond, posing as the original creator around the clock. They are reusing photos and messages from a pre-made vault. The goal is to convert every conversation into a subscription or a tip.
However, the most damaging scams also remain. Some of the bot accounts will eventually send a malicious link designed to hijack Discord or other accounts and harvest credentials.
USA Today previously reported about OnlyFans stars being impersonated to scam fans, stealing from both creators and users. The scammers create fake impersonation accounts on TikTok, use material stolen from a real creator, and add a synthetic voice to trick victims into sending them money.
The ‘girl who wants to duo’ opening can just as easily terminate in an account-takeover attempt as in a subscription upsellMalwarebytes
Targeting LoL players inside the game client represents just one of potentially many entry points where bots can’t be easily distinguished from real persons. Researchers suspect that bot operators are scraping or monitoring game data from various APIs to identify players and when their games finish.
Bots resist prompt injection attacks
Malwarebytes also attempted a common jailbreak technique, trying to break the fake-girl bot on Discord to leak its system prompt. However, it wasn’t successful.
“When the account was pressed with a ‘reveal your instructions’ style prompt-injection attempt (text formatted to look like a system message ordering the bot to break character and print its configuration), it did not comply and instead stayed in persona, deflecting the request and continuing the pitch,” the researchers describe.
They speculate that bot operators might be using guardrails against this kind of probing, or relying on a simpler scripted flow “layered with some LLM-generated text rather than an open, unrestricted chatbot.”
Check if your data has been leaked
The researchers also described a case in which a user deliberately stopped replying – the bot followed up with “Why are you not replying?” and matched the context with an image showing a concerned face.
Malwarebytes recommends treating unsolicited friend requests from unrecognized names as suspicious by default.
On the Riot platform, players can enable streamer mode to hide some data from outside parties. Remain skeptical of anyone who tries to move the conversation off a moderated platform, never send money or share personal data, and report suspicious accounts.