Hackers have found a new way to steal data from their potential victims. This time, they're using an Android game horror (with over 50,000 installs), which was found to steal credentials ' Google and Facebook players account 
The game is called Scary Granny ZOMBYE Mod: The Horror Game 2019 (Scary Granny).
Scary Granny was a fully functional game and did not raise any suspicion among users. However, on June 27, it was removed from the Play Store after some researchers discovered that the game was being used to steal credentials and collect data.
The research team reported that the game did not exhibit the malicious behavior immediately after installation, but after two days.

Also, the app was only dangerous for older Android versions. Users of newer devices running updated operating systems were not affected.
When installed, the game asked for permission to start after restarting the smartphone or tablet.
After the devices rebooted, a notification, suggesting the user to update, leading them to a fake but very convincing Google login page. The only thing that could be considered suspicious is that the “sign-in” was not spelled correctly.
After successfully stealing credentials, Scary Granny began collecting information account, such as emails, phone numbers, verification codes, dates of birth, as well as cookies and tokens.
To collect victims' data from Google and Facebook, Scary Granny used packages designed to mimic official Android applications. For example, the package com.googles.android.gms was used, which could be confusing, as it closely resembles the legitimate com.google.android .gms.
Use of false advertising
The malicious horror game also displayed ads, which supposedly advertised other apps, such as Amazon, Facebook, Facebook Lite, HaGo, Hulu, Instagram, Messenger, Pinterest, SnapChat, TikTok, or Zalo.
However, researchers were unable to determine whether these ads were being used to redirect victims to malicious sites.
However, there was one case where an ad led the user to a page that Google has blocked, marking it as misleading. This means that the game was leading users to a sitethat contained malware.
According to the researchers, hackers could exploit the game even further by asking Android users to pay a sum of money, via PayPal, to download the game.
