Let's be honest, some churches really are heavy charity and

Well there have been a number of security issues with Mikrotik, most likely your device had outdated firmware and had Winbox port accessible via WAN/External interface.The vulnerability allowed a remote user to connect to the Winbox port and obtain read access to the Mikrotik filesystem, which then allows the remote user to download the username/password database for the device, the database was implemented in a way where it was extremely easy to extract the passwords in plain text.This allows the remote user to authenticate to the device. For the mining I believe this was a SMB bug that allowed shell access to the underlying system to install/run rouge software but don really know the particulars on how it worked.IP >Socks is a RouterOS feature, it allows network devices to proxy traffic through the router, the hacked device turned on this feature which allowed random/rogue network traffic to proxy through the device, getting you blacklisted because they were probably sending spam and doing other naughty things etc.So while you have probably updated your device, the IP Socks configuration was left enabled. You should probably review all configuration settings on your device, take a backup and if not 100% confident of the configuration settings, perform a factory reset of the configuration.The default configuration of newer firmware will automatically create default firewall rules that will block external access to management ports/services, assuming interfaces are in the correct interface lists..

