There is no interception and manipulation of a download going on, at least regarding the botnet the article suggests, it came from knowingly downloading and installing pirated software. The checksum idea is to get the checksum from the official source and to apply it to the pirated download, but then the pirated download is surely modified anyway, so this wouldn't work.
It would take a lot of work. I imagine that you'd implement a link to your sites checksums in the code, which the installer would reference during installation. As long as that link is protected within code, it should maintain the validity of any checksums that the installer is referencing.