What a silly title. It may not have some active payload right now, but that doesn't mean it won't tomorrow. Seems like a reasonable strategy to spread the malware as wide as possible, then push an update to trigger whatever behavior you want. And yes, it does check for updates.
> Every hour, the persistence LaunchAgent tells launchd to execute a shell script that downloads a JSON file to disk, converts it into a plist, and uses its properties to determine further actions.