That's not (completely) true, you can easily use the SSH client (plink) without the terminal emulator. It is actually quite common to do so.
I don't think it works the other way around though.
So common I've never seen it done. Ever.
Try starting with Futty.
Well, honestly, this probably covers 99% of use cases - i.e. "I'm on Windows and I need to connect to a remote shell". Having the two separate sounds like overcomplicating things.
You download it from an unencryped, unsigned website, and there are GPG signatures available, but you can download the keys from the same unencryped, unsigned website.
A MitM attacker could easily manipulate the executables, sign them with his own keys, and do a MitM attack on the key page too.
This is not mere paranoia; we know now that the NSA has infrastructure to do such attacks fully automated and at scale.
You can't even use ECDSA, much less Curve25519-based solutions.