According to blue poster Kaltonis on the official forum:
The trojan is built into a fake (but working) version of the Curse Client that is downloaded from a fake version of the Curse Website. This site was popping up in searches for "curse client" on major search engines, which is how people were lured into going there.
The full thread (and how to find out if you've been infected) is here:
http://us.battle.net/wow/en/forum/topic/11041384892?page=1