Anyone care to guess how this is done?
The only way to open up ADB over a wireless connection is to set the device in tcpip mode on port 5555 and then connect via adb using the device's IP and the mentioned port.
However, adb is not shipped on Android devices (though adbd is). How is it that a malicious device can install an application on another device as claimed by the article?