There are several points in this post but the bulk of it is, I feel, one of those classic fallacies that journalists or security hobbyists often engage in: "I found what looks like a flaw in a system but I didn't try to exploit it for real, look how clever I am" So his mate registered a company with the same name as another company and got an EV cert. Well done. Everyone knew that was possible already, at least every…
Are you _from_ the USA? Or do you believe its propaganda from outside?
You don't need to even be able to point to the USA on a map to set up a US company and do all this paperwork. You fill out a few forms on a web page, pay a little bit of money, American lawyers sort everything else out. They keep some of the money, the State keeps the rest, everybody is happy. Oh, except your victims. They can call the cops of course, but the State obeyed the law, and the Lawyer just does paperwork. It's not a crime to be the lawyer for a crook.
Why don't crooks do this today? Well, there are two answers. For big crimes, stuff like crooked property deals, they absolutely do this already, it's completely routine. For a phishing site they don't bother because it's not necessary. If 90% of visitors to your unsecured http://paypal-credit-checking.example/ fill out the form, and you get that up to 99% by obtaining a DV certificate for it, why spend $500 setting up a US corporation for the extra one percent? But if you persuade everybody EV is great, then sure, that's what they'll do next.