Basically all of them are botnets, yes. They generally claim to have consent but I'm pretty sure 99% of it is "some app the user uses has it buried in a 200 page ToS"-style consent.
>These SDKs, which are offered to developers across multiple mobile and desktop platforms, surreptitiously enroll user devices into the IPIDEA network.
If I install an app with a big ToS and buried in there is "we use third-party monetization SDKs" and buried in there is "welcome to our botnet" they do not actually have my consent.