As I understand it, the certificate exchange is still between the client and the server; the MITM does nothing more than forward the data and insert a cleartext payload into a window of vulnerability. In this attack, the MITM does not need to know or have any certificate or cipher keys.