MONTY SPIDER is a criminal group primarily focused on financial gain, known for operating the notorious Necurs (also referred to as CraP2P) spam botnet. The group emerged around 2012 and is characterized by its large infrastructure network and continuous evolution in malware distribution tactics. While the provided input described MONTY SPIDER as an APT group engaged in cyber espionage, verified intelligence indicates its core operation is financially motivated, distributing various forms of malware, including banking Trojans and ransomware. The group is sometimes identified by the alias Spandex Tempest, although this name is also associated with other distinct financially motivated threat actors like TA505 (MITRE ATT&CK G0092) and Tidal Cyber's G3012, which can lead to confusion.