

In Linux, if you run games with Lutris, you can have them sandboxed with your sandboxing app of choice (personally I use firejail) by changing the “command prefix” option in the configuration for the game (or setting it as the default in the global Lutris configuration).
Also Lutris defaults to a different Wine instance per game, so Windows-specific malware would only ever affect the wine instance of that game.
So if you’re worried about pirated Windows games might contain Linux specific malware meant for when the game is running under Wine (as Wine is just an adaptor, not an emulator or sandboxing layer) you can go as crazy as you want in blocking what that executable can access, all fully under your control.
“You plebs should know your place”