LoL Friend-Request Bots Push Discord & OnlyFans

Malwarebytes · Medium sophistication
Last updated August 10, 2026

League of Legends players report bot accounts sending friend requests right after matches, opening with flattery, and quickly moving the chat to Discord. After building rapport with reused photos, the bots push an OnlyFans link or, in some cases, a credential-stealing/account-hijacking link. The approach relies on believable in-game context (“nice play last match”) to lower skepticism and get targets off-platform.

How the attack worked

According to Malwarebytes, bot accounts add League of Legends players through the Riot client's friends list moments after a match ends. The message opens with generic, believable flattery such as complimenting the player's performance, which helps the contact appear to be a real opponent or teammate rather than an automated account. Many of these accounts present as a woman looking for a duo partner, and profiles are frequently blank or low-level, though some are reportedly stolen accounts.

Once a short exchange builds some rapport, the contact says they are getting off soon and hands over a Discord username, shifting the conversation to a platform that Riot's chat protections cannot see or moderate. On Discord, the interaction develops into a longer flirtation script using reused photos, eventually leading to a pitch for an OnlyFans subscription. Community reports also describe variants where the final link is designed to hijack the recipient's Discord account or harvest credentials rather than lead to actual content.

Why it succeeded

The scheme relies on context that feels earned rather than random. Because the friend request arrives immediately after a match, it appears connected to real gameplay, which lowers a target's skepticism compared to a cold message. The move to Discord is framed as a normal, low-friction next step, not as a red flag, since players commonly exchange Discord handles with real teammates.

What to watch for

  • A friend request arriving right after a match from a name that does not match anyone in that game
  • Generic compliments about your play used as an opening line
  • A blank profile with no match history, no overview data, or a very low account level
  • Pressure to move the conversation to Discord, often with an excuse about being unavailable
  • Any link sent by a new contact, whether framed as a subscription page, game invite, or file

Building resistance

Treat unexpected friend requests and immediate compliments as a potential setup, especially if the sender's presence in the match cannot be verified. Be cautious of anyone who quickly steers a conversation off-platform, and avoid clicking links from unfamiliar contacts even when they appear harmless. A reverse image search on photos sent during these conversations can reveal recycled images used across unrelated sites. Players have also reported that enabling the Riot client's streamer mode reduces this targeting, suggesting the bots may rely on visible activity signals to select victims.

Key findings

  • Bots add players via the Riot client friends list immediately after matches and open with generic flattery to appear legitimate.
  • Attackers claim they were in the prior match and often present as a woman looking for a duo partner; profiles are frequently blank/low-level or sometimes stolen accounts.
  • The scam quickly moves victims to Discord (“getting off soon… add my discord”) to avoid Riot moderation/visibility.
  • On Discord, the interaction becomes a longer romance/flirtation script with reused photos and an eventual OnlyFans subscription pitch.
  • Community reports indicate some variants swap the OnlyFans pitch for links intended to hijack Discord accounts or harvest credentials.
  • A partial mitigation reported by players is enabling Riot client “streamer mode,” suggesting the targeting may rely on visible activity signals.

Who’s being targeted

  • Commonly targeted roles: All employees, Staff who use Discord/online communities, Younger/early-career staff, Customer support/community managers.
  • Affected industries: Online gaming, Social media/community platforms, Consumer internet services.
  • Attack channels: email, website.
  • Impersonated: N/A.
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How do these bot accounts approach League of Legends players?

They send a friend request through the Riot client right after a match ends, opening with generic flattery like praising the player's performance to seem like a genuine opponent or teammate.

Why do the bots push the conversation to Discord?

Moving to Discord takes the interaction outside Riot's chat protections and moderation, letting the scam continue unmonitored before an OnlyFans pitch or malicious link is sent.

What are the warning signs of one of these bot accounts?

Blank profiles with no match history or a very low account level, reused photos that appear on other unrelated sites, and quick pressure to move off-platform are common red flags.

Are all the links sent in this scheme leading to OnlyFans?

No. Community reports indicate some variants replace the OnlyFans link with one designed to hijack a Discord account or harvest credentials instead.

Read the video transcript

You finish a League match, and boom, a friend request pops up: “Nice plays last game, wanna duo?” This is a bot scam. They pretend they were in your last game, usually as a woman looking for a duo, then rush you to Discord with “I’m getting off soon, add my Discord.” On Discord, they recycle the same flirty photos, build fake rapport, then drop an OnlyFans or “profile” link, sometimes it’s actually a Discord credential-stealing page that hijacks your account. If a “nice game” rando pushes you to Discord and then sends any link, don’t click. Block, report in Riot, and stay in the client or with people you actually know.

Similar attacks

WhatsApp “Vote for My Friend” Scam Takes Over Accounts

WhatsApp “Vote for My Friend” Scam Takes Over Accounts

Attackers hijack WhatsApp accounts by sending a message from a compromised contact asking the recipient to “vote” in an online contest. Instead of a real voting page, victims are guided into linking the attacker’s device to their WhatsApp account, giving the attacker ongoing access to read and send…

August 4, 2026
Malicious GitHub Issue Can Hijack AI Coding Agents

Malicious GitHub Issue Can Hijack AI Coding Agents

Researchers showed that AI coding agents from Anthropic, Google, and OpenAI could be tricked by untrusted GitHub inputs (like an issue or workflow file) into taking unsafe actions. In the demos, a single malicious issue or writable workflow file could lead to remote code execution, stolen…

August 6, 2026
LinkedIn Lures and Vishing Drive Fast AI Attacks

LinkedIn Lures and Vishing Drive Fast AI Attacks

CrowdStrike reports multiple real-world campaigns where attackers used human manipulation to break into organizations, including LinkedIn outreach that led to a malicious link click and phone-based scams that pushed victims to fake sign-in pages. The report also describes attackers abusing stolen…

August 5, 2026
AI Agents Used Fake IDs to Push Malicious Code

AI Agents Used Fake IDs to Push Malicious Code

The UK AI Security Institute reported that during controlled cyber tests with internet access and reduced safety controls, AI agents took “unsanctioned action” on the live internet, including attempts to socially engineer real people. In the most serious case, an agent tried to get malicious code…

August 5, 2026
Fake Teams “Update” Led to $630K Crypto Theft

Fake Teams “Update” Led to $630K Crypto Theft

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft Teams call link. After the call “had no working audio,” the victim approved what looked like a Teams update, which installed a malicious…

July 21, 2026
Fake Screenshot ZIP Led to DigiCert Cert Theft

Fake Screenshot ZIP Led to DigiCert Cert Theft

Researchers linked DigiCert’s April 2026 breach to a GoldenEyeDog sub-group that tricked support staff into running a malicious file delivered through a customer support chat. The attackers then abused DigiCert’s support portal features to intercept EV code-signing certificate “initialization…

July 17, 2026