Binary replacement (replacing top, ps, netstat, etc with patched versions) is the oldest trick.
Syscall hooking kernel root kits largely only vary in how exactly they hook the syscalls - there’s a few methods, but the underlying principle is the same.
And then you have userland hooks which usually use LD_PRELOAD to intercept system calls/libc calls to get the job done.
Honestly most of the time a full blown root kit is overkill, just name your binary something innocuous and have it not do anything too fucking obvious and nobody will notice.