tl;dr A network operator can perform a MitM attack on the built-in updater, telling it a new version is available at and then downloading and running the malware