Symantec researchers have found new samples of Carberp.B online banking Trojan digitally signed with two stolen certificates. The certificates used to sign malware are typically stolen from legitimate organizations and not bought by the attackers themselves. Having two signatures on a single file ensures that even if one certificate is revoked, the file will still appear as trusted thanks to the other signature. Windows 7 and higher and Windows Server will no longer trust code signed with a SHA-1 based certificate if its timestamp is later than Jan. 1, 2016.”]