The Angler Exploit Kit seems determined to stay... as it has already infected more than 90,000 websites.
The Angler Exploit Kit (AEK) is increasingly increasing its influence on the internet since, according to analyses by Palo Alto Networks, more than 90,000 websites have already been infected by AEK, 30 of which are in the Alexa top 100,000 list.

Apparently, the number of monthly visitors to these websites is quite high, probably over 11 million, as estimated by TrafficEstimate.com.
As it appears, this is a highly organized operation in which periodic updates of malicious content are made to all AEK gate sites simultaneously.
https://www.secnews.gr/100441/%cf%80%ce%bf%ce%b9%ce%b5%cf%82-%ce%b5%cf%86%ce%b1%cf%81%ce%bc%ce%bf%ce%b3%ce%ad%cf%82-%ce%b3%ce%b9%ce%b1-%ce%ba%ce%b9%ce%bd%ce%b7%cf%84%ce%ac-%ce%b5%ce%af%ce%bd%ce%b1%ce%b9-%ce%b1%ce%ba%cf%8c%ce%bc/See also: Which mobile applications are still insecure in 2016?
Additionally, infected websites can choose to target specific IP ranges and configurations.
This is why AEK's detection rate is so low, as most of the infected sites were not identifiable even after weeks of study and scanning using VirusTotal scanners.
How does the Angler Exploit Kit evade detection?
The initial version of the AEK malicious JavaScript code was injected into compromised servers and targeted almost all major versions of the Internet Explorer Browser (version 8-11). This is because users have vulnerable versions of Flash installed on their systems.
A new variant of the Angler Exploit Kit can target all advanced, major browsers, even Gecko-based Firefox and Webkit-based Chrome.

How does it work?
When the victim visits any of the infected WordPress/Apache hosts, they are immediately redirected to a malicious server where AEK is hosted. This can happen through a middle layer called an EK gate or directly.
https://www.secnews.gr/100411/program-languages-that-generate-most-software-security-bugs/Learn: Which programming language suffers from the most security bugs?
The final malicious payload can vary and can include ransomware such as Cryptowall, spyware or botnets, which can connect the host to a C&C server. This redirection, that is, from the EK gate to the file hosting server, can occur on the same domain or cross-domain.
