Malware in 2024: New Threats Target Windows, Linux, and Even Cars

Malware authors are sharpening their tools, targeting Windows, Linux, and even car systems with stealthier, more adaptable attacks. In the latest wave, ransomware like Akira resurfaces with safe-mode evasion tactics, while a multi-functional Linux botnet named Evooo1Bot expands its reach across servers. Meanwhile, a new Windows infostealer hides in plain sight through a RubyGems supply chain campaign, and researchers uncover MacSync Stealer’s infrastructure using behavioral analysis. The stakes have never been higher.
The EDR-Evasive Ransomware Revival
Akira ransomware has evolved to reboot in Windows Safe Mode, bypassing endpoint detection and response (EDR) tools that often suspend during system restarts. This tactic allows the malware to encrypt files without interference, as noted by Huntress. The shift reflects a broader trend where attackers exploit operational blind spots to maximize damage.
Linux and Mobile: Expanding the Attack Surface
A newly identified Linux botnet, Evooo1Bot, stands out for its modular design, enabling data theft, DDoS attacks, and cryptocurrency mining on infected servers. Security firm Fortinet highlights its ability to adapt to different environments, making it a versatile threat for cloud and enterprise systems Fortinet. On the mobile front, ToxicPanda 2.0 has expanded its operations to 16 countries, targeting Android devices with upgraded spyware capabilities, as reported by Security Affairs.
Supply Chain and Cross-Platform Sabotage
Supply chain attacks remain a favorite among cybercriminals. A campaign named StubMaker compromised the RubyGems repository to deliver a Windows infostealer, blending into legitimate software development workflows OpenSourceMalware. Separately, researchers tracked MacSync Stealer’s infrastructure by analyzing behavioral patterns, revealing how attackers pivot between macOS and iOS to exfiltrate data.
Why it matters
These campaigns underscore a critical shift: malware is no longer confined to one platform or tactic. The rise of EDR-evading ransomware, cross-platform infostealers, and modular botnets signals a more sophisticated threat landscape. For users and enterprises, this means updating defenses beyond traditional antivirus—prioritizing behavioral monitoring, supply chain hygiene, and platform-specific hardening. The cat-and-mouse game is intensifying, and the margin for error is shrinking.
Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

