One may argue that there is some misunderstanding but at least immediately blocking the app in the country it undoubtedly misbehaves would be a very logical first step before digging deeper.
Why would Apple not do exactly that?
Not that Apple is in the position to put someone under arrest, but I believe LE investigations sometimes allow suspects to walk free in order to observe and collect additional evidence.
By what measures are you supposed to review an app without actually knowing how it works? How would you go about detecting malware when you don't even really know how iOS works? I don't know what's real anymore, this for sure can't be it.
Every "we use App Review to establish safety on the App Store" statement from Apple became completely worthless now.