Just for your information; rootkits can exist in any of the rings[1]. However, kernel-mode rootkits are most often harder to detect and get rid off. There are several definitions of a rootkit, a common definition is "software designed to hide the existence of certain processes or programs from normal methods of detection and enable continued privileged access to a computer."[2]
It doesn't seem like they went to any particular lengths to hide it, just nobody bothered to look very hard, and you wouldn't expect them to be installing browser plugins. Sony's DRM system, on the other hand, was an actual rootkit and went to a lot of effort to bury itself in the infected system.
[1] http://en.wikipedia.org/wiki/Ring_(computer_security) [2] http://en.wikipedia.org/wiki/Rootkit