Do we have a thread with full details on everyone who has been affected? All software installed and versions, OS, patches, windows updates on/off, last time any configuration was modified, router, ISP, location, etc?
Do we have any way to reproduce this? Does anyone with logging enabled have a record of the request? Is it happening frequently enough to run a network monitor? Do we know what coin is being maliciously mined?
The last dozen pages on Wafflepool thread have more info.