You were right to point out that this is not a virus or trojan but a problem with trust and lack of knowledge. It is a fair exploit of a feature that was poorly implemented.
In what way was it poorly implemented? How could it have been done better?
A similar trick could be done without IDN, by registering something like "paypa1.com", which looks remarkably like "paypal.com" and uses only regular ASCII characters.
Paul.