Anyways wish you best of luck stopping it. If home I would see about locking down your router. Start there for security.
I have them in my datacenter, directly attached to the internet for testing purposes. Of course it is an easy thing to put them behind a firewall, but this should not be possible... However, I reset them, changed the IPs, changed the ssh password and will put the behind a firewall as soon as I am back at the datacenter.
But it seems to be very easy to get hashpower from bitmain products without buying bitmain products...
I rather wonder how they got my ips?
One might assume by the type of traffic, or it could be someone in the datacenter