This is either done in cooperation with the Chinese mother company Tencent (deliberately delivering malicious software updates to a selected number of users), or by hacking into telecom operators infrastructure and serving targets the malicious software update on their devices
🐦🔗: https://n.respublicae.eu/bgroothuis/status/1652415851994251266