An immune system for the internet, new good samaritan malware surprises experts
Cyber attacks are getting out of control, but evolving, roving "good samaritan" forms of malware could become the new cops of the internet and the future of cybersecurity.
Key takeaways
- Security researchers have discovered a very odd new botnet that, rather than posing a threat, seems to be seeking out and destroying other malicious malware, in this case a specific type of crypto-mining malware.
- Unusually in Fbot the DDoS module seems to have been deactivated and instead Fbot searches for devices infected with a specific crypto-jacking malware and replaces it in the system, the report says.
- Discovered by the team at Qihoo 360Netlab, the variant seeks out a malware form dubbed com.ufo.miner – a variant of Android-based monero miner ADB.Miner.
Cite or link to this article
Griffin, M. (2018) 'An immune system for the internet, new good samaritan malware surprises experts', 311 Institute, 13 October. Available at: https://www.311institute.com/an-immune-system-for-the-internet-new-good-malware-surprises-experts/ (Accessed: 1 October 2026).
Security researchers have discovered a very odd new botnet that, rather than posing a threat, seems to be seeking out and destroying other malicious malware, in this case a specific type of crypto-mining malware. In short it’s the first “good samaritan,” if we can call it that, of its kind and it shows how the war against cyberattacks might not always be as one sided we think, despite the early appearance last year of another first of a kind malware, a AI fuelled self-learning malware that evaded detection for months because it learnt and then mimicked the behaviours of the systems it had infected. Furthermore, if the future forms of this malware are able to evolve then they could eventually police the internet on our behalf, protecting it from cyber attacks in the same way that the human body's antibodies attack disease - a new for of internet "immune system" that's also been posited by DarkTrace the revolutionary UK cyber security company.
Called Fbot the new type of malware is a variant of another one called Satori, which is in turn itself is based on the now infamous Mirai malware variant – a program that was used a couple of years ago to devastating effect and took down chunks of the US and European internet by executing huge DDoS attacks against the internets critical infrastructure.
Unusually in Fbot the DDoS module seems to have been deactivated and instead Fbot searches for devices infected with a specific crypto-jacking malware and replaces it in the system, the report says.
Discovered by the team at Qihoo 360Netlab, the variant seeks out a malware form dubbed com.ufo.miner – a variant of Android-based monero miner ADB.Miner.
Distributing itself by searching for devices with a specific open port, the botnet then uses a script to uninstall com.ufo.miner, if found. Fbot is programmed to scan and propagate, install itself over the malware and ultimately self-destruct, the researchers say.
Also unusually, the botnet code is linked to a domain name accessible, not through a standard domain name system (DNS), but a decentralized alternative called EmerDNS that makes addresses harder to trace and shut down.
"The choice of Fbot using EmerDNS other than traditional DNS is pretty interesting, it raised the bar for security researcher to find and track the botnet," said the researchers.
It is not yet clear if Fbot has been set up by someone with good intentions or by a rival crypto-jacker seeking to remove the competition though, but obviously many are hoping it’s the former.
The prevalence of crypto mining malware has shot up in the last year, according to various security teams, and has been found globally on systems owned by enterprises and governments alike, as well as individuals. In fact so much so that the other crybercrime tool of choice, ransomware, has now taken a back seat. Indeed, IT security firm Trend Micro reported in late August, crypto-jacking attacks spiked by 956 percent from the first half of 2017 to the first half of 2018, and among current initiatives to counter the rising threat, Firefox said in August that its browsers will soon automatically block crypto mining malware scripts with the Opera browser launching similar protection for mobile devices in January.
And as for Fbot, well, it might very well be the only piece of malware on Earth, for now atleast, that cybersecurity researchers suggest you download on purpose.
FAQ
Why does this matter?
Cyber attacks are getting out of control, but evolving, roving "good samaritan" forms of malware could become the new cops of the internet and the future of cybersecurity.

About the author
Matthew Griffin Founder, 311 Institute
Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath."
Read full bio
Matthew Griffin is a multi-award winning Futurist and expert in Disruption and Innovation, Geopolitics, Leadership, and Technology, who NASA have described as a "walking encyclopaedia of the future" and a "futurist Polymath." 15-time best selling author of the "Codex of the Future" series, Matthew is the Founder and Futurist in Chief of the 311 Institute, a global Futures and Deep Futures advisory firm working with royal households, world leaders, G7, G20, and G77 governments, NGOs, and multi-national mid and mega cap firms to help them explore, shape, and lead the next 50 years of business and society.
An award-winning YouTube creator with over a million followers, with an unrivalled global reach and impact, Matthew is a highly sought-after international keynote speaker, lecturer, and mentor who collaborates with global leaders through the United Nations Alliance of Civilizations (UNAOC) and United Nations General Assembly (UNGA) to shape pivotal initiatives such as the UN’s AI for Humanity program, the United Nations Conference of the Parties (UN COP), and the World Economic Forum in Davos.
As the former Global Head of Cloud, National Security, and Enterprise Sales for companies including Atos, Dell-EMC, and IBM, Matthew has a proven track record of building multi-billion dollar business units and turning failing divisions into market leaders. His ability to identify, analyse, and communicate the implications of hundreds of emerging technologies and trends is unparalleled, and his insights are trusted by many of the world’s most respected organisations, including ABB, Accenture, Adidas, AON, ARM, BCG, Centrica, Citi, Coca-Cola, Dentons, Deloitte, Dow Jones, EY, Google, KPMG, Lego, Legal & General, LinkedIn, Microsoft, PepsiCo, Qualcomm, RWE, Samsung, Siemens AG and Siemens Energy, T-Mobile, UBS, VISA, Walmart, Workday, Worldpay and many others.
Regularly featured in the global media including the AP, BBC, Bloomberg, CNBC, Discovery, Forbes, Khaleej Times, Telegraph, TIME, ViacomCBS, WIRED, and the WSJ, Matthews mission is to help organisations create a fair and sustainable future whose benefits are shared by everyone irrespective of their ability, background, or circumstances.
What future do you need to see?
Choose one to get started on security and privacy and the future of your organisation.
Sources and further reading
- Threat alert a new worm fbot cleaning adbminer is using a blockchain based dns en blog.netlab.360.com
- Emerdns introduction emercoin.com
- Crypto mining attacks soar in first half of 2018 coindesk.com
- Firefox announces move to block cryptomining scripts coindesk.com
- launching similar protection coindesk.com
Source: first published by the 311 Institute on 13 October 2018. Cite as: Griffin, M. (2018). An immune system for the internet, new good samaritan malware surprises experts. 311 Institute. https://www.311institute.com/an-immune-system-for-the-internet-new-good-malware-surprises-experts/
You are welcome to quote this article with credit and a link to the original.