This is one example, sure, but EV does, in general, work. And the reason why is not because it's an ironclad indefeatable process for proving you are legitimately a major trustworthy party: It's a frustrating pile of hoops to jump through. The arcane and archaic nature of getting an EV gates out malicious actors pretty effectively.
If you go through all of the process to get an EV (often involving scanned/faxed documents and phone calls), and then do something malicious with it, you're going to end up burning it (getting it revoked, generally, though, obviously the nightmare of revocation being still effectively broken comes into play) or even just the domain blocked by web filters and marked unsafe in the Safe Browsing list, setting you back to square one. All an EV vendor has to do for this to work is remember not to issue an EV again to anyone who uses the same credentials or proofs, whether or not they verified them with other authorities.
Whereas a domain-validated cert can, of course, be automated (as can domain purchasing), meaning DV certs can scale. As with spam, malware, etc., you just publish it in volume, keep changing addresses, content, etc. to evade automated filtering, and press on.
Meanwhile, if someone gets a Washington Post News EV, and starts impersonating WaPo, they only have one target to shut down a malicious actor.
I could give non-CA-related examples, but I've come to the belief recently that security and trust is often a matter of creating solutions which don't scale.