Could be an infected source code for a miner or wallet which is compiled on each platform (windows, linux etc) ...
My rigs don't have wallets running on them.
Infected source code in all sgminer, cgmniner, bfgminer, and even Cudaminer? Code I've downloaded from github and compiled myself in each case?
Seems highly unlikely. Possible, but very unlikely.
You seem to have a good sampling of configurations, so it seems like agood place to start. Do you they all run on the same local area network? If so, are they using private ip addresses with your router running network address transalation? Are they dynamically assigned or manually entered into the configuration of each mining computer?
Yes, all running on the same local network. Some are using static IP's and some dynamically assigned IP's via DHCP from the router, which is running proprietary software from the router manufacturer, though some of the rigs are bridged to the router via another router running open source dd-wrt. Quite a few different variables here. All are using Google's DNS, 8.8.8.8 and 8.8.4.4.
When the problem occurred, it happened on all rigs simultaneously, regardless of OS, miner software, static or dynamic IP, router connection, etc.