Required review by Apple? That malicious code is restricted from doing much precisely by the sorts of things OP is complaining about? The potential economic return isn't as high because Apple can forcefully clean it off? That it's harder to be anonymous when $100/year has to change hands for a cert and Apple wants to know who you are on some level so it'd be at least somewhat harder to avoid them going after you? None of these are bulletproof, even combined. But even so they're not worthless either to that goal. Are you actually asserting that the actual state of malware on iOS is identical or worse then that of Android or Windows/Mac/Linux? That's not something I've seen supported before but I'd read a good source if you've got one.
0. Trying to prevent average developers from shooting themselves in the feet too often by having apps that depend on external servers to run, then having a big security incident and Apple being blamed for allowing insecure, third-party code to run.
1. Trying to keep tabs on devs pivoting too far without a re-review. Can’t sell a Farmville app that then becomes a bitcoin wallet which then steals said bitcoins.
2. Keep the quality of apps up by curating through review rather than allowing free, unlimited publishing of random/broken apps. It’s a small barrier to entry and proof that someone invested to make something worth publishing.
3. Malware for old/jailbroken iOS existed way back, but it’s not really a thing, anymore because 0days get mostly either reported to Apple or sold/auctioned off.
This limitation is not about improving security, it's about preventing developers from creating ecosystems inside their apps.
But sure, you totally know how to sneak malicious code past Apple's security processes, and for some completely sensible reason you've neither used it for your own nefarious gain nor reported the exploit and claimed the fat bounty that would inevitably await you.