For those that don't want to read the whole thing, (supposedly) the attackers reached out on linkedin to a bunch of employees asking them to apply to a fake company. One of them did it, went through a bunch of fake interviews, and then got a fake offer, in the form of a PDF. They opened the PDF and that installed a keylogger on their system (it doesn't explain how). The attackers then used that engineer's credentials…
Sounds like a bad RPG plot. "Because of its danger, we broke the Obsidian Key into 9 pieces and divided them across the realm, each protected by a powerful, mystic dungeon. Also, Dave can access them any time he says the secret word."