The problem is that even if you can amass such an IOT botnet, you still need people on the ground to conduct such burglaries, and that scales poorly. Even if you tried to operate on a SaaS model, you're going to find that your clients (ie. drug users who want their next fix) are fickle and are very eager to snitch on you to the police, making it very likely that your botnet gets dismantled. On the other hand running a DDoS or "residential proxy" botnet comes with none of these hassles.
Also, while "smart" Samsung fridges are the topic of this article, the concept generalizes to any internet connected devices within "smart" homes which exhibit a combination of "hackable" and revealing-of-occupancy. Samsung refrigerators are unlikely to be the most attractive vector when there are e.g. "smart" light bulbs out there which are vulnerable and never going to be patched because the manufacturer went out of business.
FWIW, I'm not a pen tester or security specialist — just a security-conscious generalist software developer. I see evidence left behind of scanning attacks in web logs, but haven't actually crafted such mass attacks myself.