I wonder if scammers are intentionally misspelling subject lines because most security savvy people will just delete those as obvious scams and move on. This would have a two pronged effect:
1. it would filter out security savvy individuals from the actual payload, who might report the scam.
2. it would map to the least security conscious individuals who would be the most likely to fall for it.