Ok guys thanks for all the feedback. You guys did get my head working in a different direction. So as it turned out, they did hack the ILO since it was accessible via the internet, and kept infecting it from there.
I was able to find the cronjob and scripts being installed and was able to stop...