This paper conducts a large-scale measurement of code-signing abuse using over 3.2 million signed malware samples, revealing the global prevalence, evolving attacker strategies, revocation weaknesses, and real-world use of certificate polymorphism to evade detection and revocation.