This seems like a refinement of "tap-jacking", which is a pretty well-known UI redressing attack for Android apps, and works in a way that is somewhat similar to "clickjacking" on web pages --- an invisible frame is rendered on top of the application that captures inputs (as opposed to an opaque frame that obscures the legitimate application and tricks you into interacting with it).
The big limitation on these attacks is that you have to install a malicious application and then trick people into getting to a situation where the application can interact with a specific target; that's something that should be straightforward for app stores to screen for.