Security companies have identified multiple malware threats that use stolen digital certificates to sign their components. Windows operating systems rarely check certificate revocation lists (CRL), or don’t check them at all. Malware authors are interested in signing installers and not just the drivers, because antivirus solutions assume that digitally signed files are legitimate and don’t scan them. Many use digital certificates bought with fake identities, but the use of stolen certificates is also common, experts say. Stuxnet used in 2010 was discovered with rootkit components that were digitally signed with certificates stolen from semiconductor manufacturers Realtek and JMicron.”]