It would allow the malware to get around any software firewalls.

Which it would already have control of with root access.

It would, but it would need to deal with the whole plethora of software firewall to ensure it doesn't trip them but doesn't break them in a way noticeable by the user. Piggybacking on Windows Update accomplishes both because every software firewall has Windows Update whitelisted out of the box.

