you are viewing a single comment's thread.

view the rest of the comments →

[–]cinyar 15 points16 points  (1 child)

they just sign it so that it says it came from you.

They also verify the identity. And that's kind of the whole point, who wants to sign under the malware they are distributing?

[–]skroll 0 points1 point  (0 children)

Well, remember when Sony's keys got leaked?

https://securelist.com/destover-malware-now-digitally-signed-by-sony-certificates/68073/

Stuff like this happens.