AiTM attacks don't steal passwords; they copy the result of a real login. You need to watch what happens after the user logs in to catch a hijacked session.
Stolen browser sessions and authentication tokens are becoming more valuable than stolen passwords. Flare explains how the ...