[tl;dr] using tools such as virustotal, it is possible to find leaked code signing certificates The leaked certificates represent authentication keys that validate legitimate access to protected content, and their compromise undermines the fundamental trust model upon which drm systems operate For some, the password can be cracked, after which they can be used to sign malicious code
Does Malwarebytes scan .sys files - detect leaked certificates? - Malwarebytes for Windows
In this blog post i explain this process, including responsible disclosure measures.
Here's how to defend against it.