Cloud-native malware is evolving to become nearly invisible, blending into legitimate processes, using rootkits, process mimicry, and in-memory payloads to evade detection. Based on original research, this session will expose stealth campaigns like Koske and Perfctl, reveal their economic motivations, and demonstrate how open source tools can detect these threats and close security blind spots.