How the attack works

The victim signs in to a convincing replica that forwards everything to the real site and captures the resulting session.

What still resists it

Passkeys and hardware security keys, because they bind the credential to the real domain. A relayed sign-in simply fails to authenticate.