How about we go full meta and suspect the linked PDF is the malicious payload vector?
Supply journalists with harmless USB devices. Then pass around a fully weaponised PDF.
For the those that think malware in PDF's are history, here's a link to 2 zero days found just this march.
https://cloudblogs.microsoft.com/microsoftsecure/2018/07/02/...