Fake party invitations - Spam getting through
Problem reported by Douglas Foster - 9/3/2026 at 4:45 AM
Submitted
I am seeing a new attack technique centered around anonymous party invitations:  The recipient has to click the link to find out the details of who the party is for and when it is occurring

I have four examples from Gmail and one example from Yahoo.   The subject lines were all different:
  • RSVP: Invitation from Arlene Malone
  • Arlene Malone sent you an invitation
  • Shukriyyah Payne INVITE YOU
  • Join Us to Celebrate a Milestone
  • SPECIAL INVITAION
  • REMINDER: Your invitation is ready!
  • COME CELEBRATE THIS SPECIAL OCCASION WITH US
The message bodies were also unique.   Some used references to Punchbowl or Evite, some did not bother.   The Gmail messages had this header field:
  • X-Forwarded-Encrypted: i=1; <meaningless string, base64-encoded>
  • To: undisclosed-recipients:;
The one from Yahoo did not have a To: header at all.
It also had this header field, which is probably irrelevant, but I am grasping at straws:
X-Mailer: WebService/1.1.26380 YMailNovation

It may become necessary to quarantine anything come from unknown Yahoo and Gmail addresses, regardless of detected risk, but doing that would be pretty disruptive to our legitimate traffic.
SmP Replied
Truly thought that I was special and had already RSVP'd to Arlene. This special occasion seems less special already.
Douglas Foster Replied
I got a laugh out of your wisecrack.   On investigation, I discovered that these attacks have been trickling in for the last two months.   It appears that the wisdom of my users or the effectiveness of my web filtering have combined to avoid disaster.

Some of the messages actually say, "Open on desktop for best resuts!"  (which ensures that the ransomware has a juicy target.)

I have pulled a list of acceptable and unacceptable senders that use "undisclosed recipients" or have no  "To::" entry at all.    Two Delcude filters now ensure that the allowed senders can continue to use that technique, while similar messages from any other sender be sent to quarantined.  The known-bad senders have been blocked.

I have also created a quarantine rule to quarantine any message that contains "open on desktop". 

Now to see if that defense is sufficient.

Reply to Thread

Enter the verification text