I wonder how you concluded that such a hack takes 10 min. to code?

It is advanced with the features you are requesting and it sure takes much more than 10 min.
I suggest:
* change your password to a complex one like 65hr5ywcv.65
* In your password use chars that does not exist in English language like ???????????
* put a second password to your admin dir via .htaccess
* Trace attacker IP, find his ISP (unless he is using proxy) and complaint to them with your logs