If an attackers rouge process lands itself on a target, using something trusted like cURL is better than opening a socket directly, no? Less likely to attract attention?
Same goes for wget, links, etc.
Sorry no sources, it won't take you long to verify this yourself using google. I'm sure there are competent infosec guys and gals here who can provide a better explanation.