ok, I can't say too much, because they are still trying to figure out the source, but here is what I do know:
It was a keylogger, and they use it ONLY to steal WoW accounts. There is a very regular pattern, but it seems to involve WoW-related websites, and addon-download sites.
And of course, there is lots of stuff for people who buy gold, powerlevel service (not like the fast-level guide we use/posted up here, which is legit).
What happens is people using IE or a not-too secure Firefox go to a site like Allakazam, or to d/l an addon from a semi-secure site, like Curse gaming. When you mouse over a ad window, or go to close a popup, or choose the wrong mirror, or enter login info for a forum, it happens.
The keylogger installs, and then waits for you to enter your info for either the game or WoW forums, or similar sites (LIKE FORUMS!!!! IF YOUR WOW LOGIN INFO IS SAME AS HERE, CHANGE WOW PW NOW!!!). It takes pictures, and sends it to the hacker.
then, here is what will probably happen:
a filter bot compares the info to Armory or other model/character sites (like wowhead). If it is a high-level or guild-leading type, an alert pops up - because the hacker gets THOUSANDS of hits every day; they have to choose the 'best' people to try to hack.
The hacker will log in - weekend is better, because less Blizz customer support - or at really offpeak time. First, they change password aAND your secret question, to buy time.
Now, they look for highest level enchanter, and start there.
All items will be DE-ed or vendored that can. gold raided. many things deleted just to be mean. An enchantre is chosen, hopefully one with guild bank access. If not, the person may drop a profession, and powerlevel enchanting and/or alchemy - so they can DE guild vault , bank and inventory items, or make stacks of potions to move out.
Then, it gets bad.
If 60+, they go to Shadow Lab or Slave pen, and use a speed/teleport hack to get to a chest. They try to open them & loot before dying, and reset. This is all probably done with botting programs. They want the blue items, and this is fastest way - again, for DEing. GMs catch them a lot at this point, at whcich time you will be banned for 'game mechanics exploitation.'
They may join high-level PUGs for the same purpose - to ninja & hearth.
Or they may just run around naked, cursing, harrassing. Or trying to spam gold buying/selling/powerleveling services. If you get banned, it just buys them more time while you have to figureout how to file a complaint through e-mail.
Sometimes, a high-level character will be put in for realm transfers - they are hoping to either sell it off, or to use it to commit more wow crime on another realm. If your credit card info is with wow, then the hacker can just do a 'paid realm transfer.' They did that with Rae (but she is on her way back to CC now), and they either deleted Gatlin, or tried to tranfer him (we are waiting to find out).
Or, they may just delete the character.
There are 2 known gangs doing this - 1 in China (college students) and 1 organize crime ring in Russia.
As of now, these hackers ONLY want wow stuffs - because it is a very low-ranked cybercrime; almost impossible to trace/prosecute internationally, and not as harsh punishment as stealing credit card info, driver ID, govt. ID, etc.
There are a few things you can do to help/reduce the chance, but not many - this is a VERY sophisticate attack plan!!!
End of Part 2 >.<