@Manish Kumar Thanks for reaching out. The attack mentioned in the article has been targeted to users to look legitimate and use the benefit of less secured Authentication methods (Like No MFA or other security keys Like FIDO).
Any Advance protection tools look for suspicious flag like blocked flagged domains, spoof intelligence and lots of other things. While we do have many services at place to prevent phishing and other known attacks, like
Anti-Fishing protection in Microsoft 365
Spoof Intelligence in EOP and Configure anti-phishing policies in EOP
but despite all these things a hacker would find something to attack unless we build the core strong with something they cannot have.
If you look at this image you would know the importance of password less authentication
So if we are really to prevent these kind of things, you must consider :
The organization should also educate their high risk user about this kind of attempts and use this attack simulator to spread awareness :
If the suggested response helped you resolve your issue, please do not forget to accept the response as Answer and "Up-Vote" for the answer that helped you for benefit of the community.