Recruiting your users' systems into a botnet is not an acceptable way to make an app "economically viable" any more than, say, installing a rootkit on their systems.
Is Google Maps a botnet because all of the clients share location data to make navigation more optimized? Having multiple users connecting back to a central server does not make something a botnet. Users should be able to decide for themselves whether they want apps like this or not.
The difference of course is that Popa does not provide 1. informed consent to users and 2. actual useful app functionality. The user does not know when an application is using the Popa SDK and does not know their device has been compromised. It is bundled inside seemingly legitimate software without the user's knowledge. Therefore, the user cannot make an informed decision about whether to use the app. Also, unlike the Maps example, the botnet provides no feature that the user would want or choose.
Popa is an illegitimate and botnet[1] that no end user knowingly/willingly uses.