I'm not really sure if that is true. Adobe exploits are pretty cheap and unless your target is in software you can usually get a click on a link one way or another.
Really, to me, the hard part is getting in without needing to have the user consciously do anything since then you're in and nobody could even have noticed you doing something.
That's why I said remote/browser, everything else is noisy and therefore the 'easy' route. Usually this is sufficient for low tech nation states because they attack organizations not individuals, so all you need is a weak human link where noisey isn't a big deal. Then moving horizontally across the organization.
But more importantly OS are terribly insecure and privesc bugs are a dime a dozen. You don't need zero days to achieve that the vast majority of the time.
But a browser exploit isn't. They're a dime a dozen. Also, I'm surprised that email is still a primary vector that's used to get people to click on links with their work computer. It seems like such a monitored method compared to, say, a LinkedIn contact.
[1] http://www.istartedsomething.com/20090611/uac-in-windows-7-s...