You're downvoted, but I'm certain this is exactly what it is.
That trick doesn't work anymore for any reasonably modern email client.
That's when you remind him that your boss needs to get this role filled by the end of the week so if you don't get a response by tomorrow you'll have no choice but to offer the job to another candidate.
You can put it into a .zip archive or just send an email containing a link with a fake PDF
This sounds way too sophisticated for them to risk it with a "Offer.pdf.exe". Especially if it was state-backed. If the victim notices it, and the bar isn't high, you'd basically spook him away and alert the entire company.
I'm not sure it was even an exploit. It could very well be an intentionally-malformed PDF that pretends it has to be opened in a special "viewer" software, maybe even Adobe- or DocuSign-branded.
You can easily embed arbitrary javascript into any PDF, and you can obfuscate it pretty well enough to get past most endpoint security tools on the market.
That JS would be sandboxed similar to in browsers, so you'd still need an exploit to break out of that.
Not too tough, if you're a state backed group. Just buy one.
The going price for Adobe PDF RCE zero-days is $80,000
Is there a good no-nonsense way to clean PDFs of possible threats? Hunting around I see mentions of converting PDF->Postscript->PDF to remove junk, but I also see mentions that Postscript is its own security mess.
Your only option is to disable all of those fancy features. That config only lasts until someone needs to file a form with the government though.
You don't even need JS in a PDF. PostScript remains a Turing Complete language on its own.