3/3 They had some fun stuff to mask the mining program pretending to be "oracle" or "my_sql" and "python" even though it's clearly not those programs.
Lessons learned: disable password authentication on SSH logins; check your crontabs; delete any old user accounts