Your post switched half-way from "this hypothetical app your mum might hypothetically install" to "this apparently real app doing these specific things". Which way is it? Are you describing an actual threat in the wild, or just speculating about possibility?
FWIW, similar kinds of attacks is exactly why side-loading apps is about to require a reboot and 24 hour cooldown. Which you mention at the end. It sucks, but it's a decent compromise; power users like me will just do the dance and pick the "indefinite" option the moment they unpack their new phone, and rest of the people will never even know about it until they're half-way through being scammed.
I personally don't believe doing anything more in this direction is warranted.