Hacker News new | ask | show | jobs
by geococcyxc 4130 days ago
Because it is needed to decrypt the key and as the program uses it, it must be in memory (at least at some time).
1 comments

Ahh. That makes sense. So the malware itself is decrypting the certificate using the password.