Digital certificates are valuable resources to threat actors, as their mere presence can reduce the chance of early malware detection. The identity behind the origin of information is the one that is used as the key measurement of trustworthiness. Threat actors are so focused on impersonating trusted parties that they are focused on acquiring the best digital certificates one can get their hands on. The following is a complete timeline reconstruction of a successful executive impersonation attack that was used as a vessel to obtain a valid digital certificate. We also illustrate stolen certificate misuse in signing and distributing malicious content.”]

