For several months, a technique known as ClickFix has been one of the preferred methods used by hackers. This method relies on a victim installing malware themselves, often after being prompted by a fake error message or CAPTCHA verification to copy and paste a command into the "Run" window in Windows. However, according to a report published by Microsoft on September 29, 2026, Star Blizzard, an advanced persistent threat (APT) group attributed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to the FSB's Center 18, has returned to a more conventional method. Microsoft has renamed this new approach RedFlick, which involves a classic hacking technique: infected email attachments. Hackers using RedFlick send emails with seemingly harmless content, such as an invitation to a conference or roundtable signed by a well-known think tank. If the target responds, they receive a ZIP or RAR archive protected by a password, which is communicated in the form of an image to avoid detection by email filters. Inside is a file that appears to be a PDF but is not. When the victim double-clicks it, a real document opens on the screen to reassure them, while scheduled tasks in Windows install CosmicPulse, the malware signature of the Russian group. This click remains the only action required from the user. There are some new elements in the RedFlick technique. In some cases, the hackers hid their file in a virtual disk image (VHDX), which is less monitored than typical email attachments. In others, they concealed part of the malicious payload inside a PDF. Additionally, the entire infection process relies on tools already present in Windows, such as ssh, curl, or the Control Panel, making the attack more discreet than a classic executable file. Microsoft does not explicitly state why Star Blizzard abandoned ClickFix, but its report provides several clues. The group regularly revises its methods, often after being publicly exposed, and these changes followed the publication by Google in October 2025 of a report on one of its malware. The group is referred to under the name ColdRiver in the report, with each publisher using its own designation. The report also emphasizes a more practical aspect: since January, the group has shifted from targeted attacks to mass campaigns, with tens, if not hundreds, of emails per wave, which presumably requires an automated sending platform. However, ClickFix, which requires several actions from the victim, is less suitable for this type of operation than RedFlick, which only requires a single click.