The trojan is built into a fake (but working) version of the Curse Client that is downloaded from a fake version of the Curse Website,” said Blizzard. “This site was popping up in searches for “curse client” on major search engines, which is how people were lured into going there."
“At this point, it seems the easiest method to remove the trojan is to delete the fake Curse Client and run scans from an updated Malwarebytes. Should you still have issues, there is a more manual method posted earlier in the thread. Most security programs should be able to identify this threat shortly.”
News by Luca Rocchi and Marc Büchel - German Translation by Paul Görnhardt - Italian Translation by Francesco Daghini