I'm not sure you are looking in the right place, while MODX is one possible attack vector, it sounds like the server was compromised/rooted. I can think of several questions I would be asking my hosting provider:
- What version of Apache is in use, and was it vulnerable to any exploits that could explain the problem
- Why wasn't this problem caught earlier
- What steps have you taken to ensure our server is secure
- Do you have any information on how they might have accessed the server
- Did you check for any backdoors, if so what was the result?
If the server was unmanaged you need to be talking to your server administrator, as you should have measure in place to prevent problems like this one. If the server was managed you need to be looking at how this went undetected, and evaluating if their management skills are to be trusted.
Personally my first step would be securing a new server, locking it down, moving the site, and ensuring it's been locked down as well. I wouldn't trust a server that has been compromised at the service level.
That being said depending on what version of MODX you had installed there are several attack vectors that could be used for initial access, and if the server wasn't secured used to elevate access to the server. The same can also be said for anything installed on your server, such as Apache exploit(s), Control Panel exploit(s) - If you have a control panel installed, insecure login permissions, etc.