Earlier quoted context omitted.
No need of (2) and (3) - the user can choose to not install/use the app. (1) is the right fair boundary.
Those apps just shouldn't exist. I don't know how "join your users to a botnet" became some kind of legitimized monetization scheme. Ads are bad enough. What's next? "Participate in a DDOS in order to use our app?"
If there are proxy apps that only do the latter sort of work than I'm actually in favor of them existing and being widespread.