This tutorial outlines a phishing technique called the "Friend Chain Method" used in Roblox to trick players into revealing their account credentials by leveraging trust and social engineering through Discord.
Step 1: Compromising a Roblox Account
Objective: Gain access to a legitimate Roblox account to exploit the trust of its friends.
Process: The attacker targets a Roblox player who has fallen for a previous phishing scam. Once the account is compromised (e.g., through stolen credentials), the attacker uses it to impersonate the legitimate user.
Step 2: Prompting Victims to Share Discord Contact Information
Objective: Trick the victim’s friends into providing their Discord usernames to move communication to a less moderated platform.
Process: Using the compromised Roblox account, the attacker sends private messages to the victim’s friends list in Roblox. The message is crafted to sound urgent and personal, leveraging the excitement of a new game, e.g.:
Hey! My Discord account got deleted, so I made a new one. Add me quick at [Discord username]! A new Roblox horror game just dropped, and I want to play it with you! 😱
The attacker avoids sending a phishing link in Roblox to reduce suspicion and bypass Roblox’s chat filters.
Step 3: Sending Phishing Links via Discord
Objective: Deliver the phishing link through Discord, where users are more likely to trust direct messages.
Process: Once the victim adds the attacker’s fake Discord account, the attacker sends a follow-up message, e.g.:
Yo, the new horror game is insane! You need to join the event to play with me. Sign up here to get access: http://roblox-horror-event.com/login
The link leads to a fake Roblox login page that mimics the official site (roblox.com
). The page prompts users to enter their username, password, and sometimes 2FA code, under the pretext of “verifying your account to join the event.” The Discord account may use a profile picture or username similar to the compromised Roblox account to maintain trust.
Step 4: Creating a Viral Effect
Objective: Encourage victims to unknowingly spread the scam further.
Process: After a victim enters their credentials on the fake login page, their Roblox account may be compromised. The attacker repeats the process using the newly compromised account, messaging the victim’s friends in Roblox to collect more Discord contacts and continuing the cycle on Discord with phishing links. The attacker may also join public Discord servers related to Roblox (e.g., for Adopt Me or Blox Fruits) and post similar messages about the “new horror game,” spreading the scam to a wider audience.
Why This Method Is Effective
Trust Exploitation: Messages from a friend’s Roblox account, followed by a seemingly legitimate Discord account, build trust and reduce suspicion.
Platform Shift: Moving from Roblox’s moderated chat to Discord bypasses Roblox’s strict chat filters, making it easier to send phishing links undetected.
Excitement and Urgency: The promise of a new horror game and the urgency of “add me quick” exploit the excitement of Roblox’s community, especially younger players.
Social Engineering: The attacker uses a conversational, friendly tone with emojis and game-specific references (e.g., “new horror game”) to blend in with the Roblox community.