Why do they gloss right over how this was distributed? Barring details of any other kind of exploit we would have to assume the vendor's update server was compromised? If so why don't they just say so.
I found all these details through examining the official firmware image and reverse engineering.
I don't remember if I reported Google Ads id to Google. It is interesting that Google doesn't notice and care about such use of their products.
You say "compromised". I say "monetised".
:sigh: