Why not? They can get them for $99 and the rewards will likely net them thousands of dollars before Apple catches on and revokes their certificates. If you want cost to be an obstacle to malware authors, it needs to be more than a measly $99.
This is simply a mechanism for Apple to stay ahead of any worm-like activity and they decided to attach a barrier to entry ($99) and recoup a pittance while they're at it.
It also gets Apple more information on the developer, should the company ever want to track them down. A payment history leaves a wider and longer paper trail.
I'd also assume that Apple blacklists any certificate if the developer used some sort of fraudulent payment. I'd hope so, in fact.