Researchers at security firm ESET have discovered a malware that steals Facebook login credentials. The trojan has disguised itself as an Android game and has been downloaded a million times to date.

ESET's Robert Lipovsky reports that the game Cowboy Adventure, as well as Jump Chess, were downloaded by users of the service a million times before they were removed from Google Play for stealing Facebook credentials.
The scammers had created a seemingly legitimate game by copying popular titles, adding malicious code that stole Facebook passwords from phishing websites opened through the malicious games.
Lipovsky reported that “… although the number of potential victims was one million, there were many of them who had not been deceived by the scam.”
"Our analysis of these malicious games showed that the applications were written in C# and used the Mono Framework.
“The phishing code is located inside TinkerAccountLibrary.dll. The application communicates with the command and control server via HTTPS, and the address to which it sends the collected credentials is loaded to the server dynamically.”
