Their effort to obfuscate their tracks does sound pretty nifty, but part of me is disappointed that it all depended on the target clicking on something they shouldn't have. Glorified phishing schemes just don't have the pizazz of a remote buffer overflow exploit, for example.