A Malwarebytes analysis investigates flirty accounts promoting OnlyFans pages on X to see if their replies are scripted, AI-generated, or written by real people. The researcher, Álvaro Martínez Majado, found accounts that followed a highly repetitive conversational pattern—opening with casual, flirtatious banter and asking similar qualifying questions—consistent with a commercially driven outreach campaign aimed at identifying responsive individuals and steering them toward paid pages.
At the same time, some interactions showed more flexible, context-sensitive replies, suggesting a hybrid approach that blends scripted messages with an AI-enabled conversational layer to handle unexpected questions.
The evidence is not conclusive, but it points to a system that can both maintain scripted structure and adapt output in real time. For example, an instruction encoded in hexadecimal prompted a reply, and a test demanding exactly 12 characters produced an undercounted but recognisably corrective response. Voice notes were also used, with some messages spoken aloud or generated via text-to-speech, leaving unclear whether a human or an automated tool produced them.
The article stresses that traditional bot tests may be less reliable, as the line between human and machine becomes harder to discern. Practical guidance includes treating unsolicited messages with caution, avoiding transactional prompts, and reporting suspicious accounts; the core takeaway is to assess what the account asks you to do rather than how convincingly it talks.