Another alternative... a virus which looks a lot like being coded by the NSA or a similar agency is now found and in the open to be analyzed by everyone. It turns out that it's using a Microsoft signature. Microsoft needs some explanation which isn't completely pissing off all it's customers in the middle east, or wait - let's make that any state-customers worldwide. Yeah, crazy conspiracy theory stuff, I'll put on my tin foil hat now.
No, I think the MD5 collision hypothesized by rb12345 above makes a lot more sense. Someone went out and audited the full set of code-signing certs, discovered this oddball one, and exploited it. There's no secret in the process that couldn't have been discovered by a suitably determined attacker. It was a very understandable MS process goof that allowed this oddball cert to live.
Yeah, the strange part is just that we're talking about a virus which according to all reports is mostly used for attacks on the middle east. And according to the Kasperksy guys it has a complexity that hints a lot at state sponsorship. We just learned this week that the US has a cyberwar program and works there together with Israel - and that's not even some crazy conspiracy theory but officially acknowledged. Also an Israeli minister hinted that they would use such tools hours after the flame news got reported. The question is - would such an agency rather try to hack the Microsoft certificates or simply ask and tell Microsoft to prepare a good excuse once it blows up? I mean if flame was written by anyone else I'm pretty sure they hacked Microsoft, but that would mean there's someone out there now writing viruses at a level which makes virus experts from Kaspersky think that it can't be done without state sponsorship. Or we have the NSA hacking Microsoft now - well, that would be at least some fun.
If I were a spook, "asking microsoft" would seem like a huge compartmentalization and classification risk. If you were already sitting on an exploitable cert already in the wild, why bother?
If they were going to make this up, they would simply say it was stolen, or the NSA would have had a front company setup for years with some plausible reason for having access to the certificates.