August 14, 2010, 11:17 AM — Don't look now, but that "LinkedIn" invite you just received from a "colleague" may in fact be yet another cleverly disguised piece of spam.
Over the past 24 hours I've received more than 20 variations this piece of e-junk, almost all of which slipped past my spam filter. Most of them include the line:
"[Insert name here] has indicated you are a Colleague at Interbrand."
My email client (Thunderbird) blocks images automatically, but when I told it to load one I got this ad for male performance enhancers:
Which I have to admit is pretty funny. Clearly this is not a phishing attack; the spammers here are just exploiting people's trust in LinkedIn to get them to open the email, in the hope of enticing the curious and/or stupid to click that link.
In this case, all the links lead to a Web site called PathTasty, which bills itself as "Canadian Pharmacy -- #1 Internet Online Drugstore." A Google search for that turns up this McAfee Site Advisor review, which is anything but magical:
"Canadian Pharmacy" / "European Pharmacy" / "Canadian Healthcare" is an illegal and dangerous pharmacy operation run by the Russian criminals Igor Gusev (Игорь Гусев) and Andrey Smirnov (Андрей Смирнов) and their affiliate program Spamit/Glavmed (Спамит/Главмед).
You seldom see greedier scumbags than these criminals. They don't care how much damage they cause to innocent people as long as they get all they want. No matter if people get seriously ill or even die after taking their fake drugs, or lose their money after giving over their credit card details. They would be happy to sell their own mother for a quick buck. But of course they don't have one – this kind of filth breeds in drains."
Nice. Other LinkedIn spam isn't so obvious or so benign though. I also received fake invites that lacked the Viagra Houdini image but still lead to weird sites (like one called "Cernoma"). When I visited that site, Google Chrome tossed up the following warning: