They found the loader, updates here:
http://www.symantec.com/connect/w32-...ro-day-exploit

It didn't get less interesting.