That technique has been in use by a zeus banking variant for over three years now. There was a completely independent malware strain found at the beginning of this year that does the same and a big fuss was made about it. Was end of 2010/ or beginning of 2011 the method was first seen in malware.
Plenty of apps out there that anyone can download to intercept sms and forward them to another phone without the user knowing too. Probably find some of them on the play store too.
The more people use two factor authentication, the more common this will become in other malware. Time for 3 and 4 factor authorisation with passcode, fuzzy logic and quantum bits