How the attack works
The victim signs in to a convincing replica that forwards everything to the real site and captures the resulting session.
What still resists it
Passkeys and hardware security keys, because they bind the credential to the real domain. A relayed sign-in simply fails to authenticate.