Several of the forum comments mention fresh installs. So possible, but fairly unlikely.
Fresh installs from what media though? "Pre-activated" Windows ISOs are freely available on any torrent search site with who-knows-what added.
That is a main issue with people who don't know how to look for the right ones. But I get my images by matching the MSDN MD5 hashes (I am not on 10 yet, even though digital river is gone the MSDN images are still out there)
Wouldn't that malware just download and install payloads itself rather than piggybacking off of Windows update? It would need root access to manipulate Windows Update in this way, but with root access it wouldn't need Windows Update to install packages.
It would allow the malware to get around any software firewalls.
Which it would already have control of with root access.
It would, but it would need to deal with the whole plethora of software firewall to ensure it doesn't trip them but doesn't break them in a way noticeable by the user. Piggybacking on Windows Update accomplishes both because every software firewall has Windows Update whitelisted out of the box.
Agreed, and there are so many possible explanations that jumping to "Windows Update was compromised" is just silly.