Research

Researchers track Chinese AI 'agent fleet' hitting Alibaba's Amap

Independent researchers found an 'agent fleet' running on Tencent infrastructure and systematically querying Alibaba's Amap for directions to public-venue entrances, based on URLquery traffic logs published Sunday.

Researchers are tracking a Chinese AI ‘agent fleet’
Researchers are tracking a Chinese AI ‘agent fleet’AI-generated
By James Calloway5 min read

Updated

Why it matters

  • Independent researchers posted preliminary findings on Sunday describing an AI 'agent fleet' running on Tencent infrastructure.
  • The agents systematically queried Alibaba's Amap for directions to entrances of public venues, including a park, a zoo, and a hospital.
  • Researchers rejected the term 'swarm,' writing that there was 'no sign of communication between' the parallel agents.
  • The fleet was discovered through URLquery traffic logs, the same method that previously surfaced long-running activity by OpenAI agents.

A fleet of Chinese AI agents is probing Alibaba's Amap mapping service from Tencent's infrastructure.

Independent researchers posted preliminary findings on Sunday describing what they call an "agent fleet" — a cluster of parallel AI agents issuing coordinated-style queries to Amap, Alibaba's consumer mapping platform. The activity surfaced through traffic to URLquery, a domain-scanning service that logs automated visitors and the sites they touch.

The disclosure comes in the wake of the Hugging Face rogue-agent incident and lands as a growing number of research groups treat AI-driven web traffic as a measurable, monitorable phenomenon.

What did the agents actually do?

The agents fired a steady stream of requests at Amap's directions API. Each request asked for routing data to a specific entrance of a named public venue, the report said.

The targets observed included at least three categories of public places:

  • A park
  • A zoo
  • A hospital

The agents were not attempting to breach the service, according to the researchers. They appeared to be sidestepping Amap's published API rules, using a consumer-facing interface to extract entrance-by-entrance data that the public map product exposes by default.

Why "fleet" and not "swarm"?

The distinction runs deeper than branding. The researchers explicitly rejected "swarm" because the agents showed no signs of communicating with each other.

"Agent fleet, not swarm: many parallel agents on the same kind of task, with no sign of communication between them," one of the report's authors wrote.

That wording places the activity closer to a distributed scraping operation than an orchestrated multi-agent system. Each agent appears to run the same job alone, drawing on Tencent-hosted resources without a visible command channel connecting them.

How were the agents discovered?

URLquery, a service that fronts web requests on behalf of AI agents and other automated clients, did the work. The platform loads websites that agents cannot reach directly and archives the responses. Those archived logs have become a free feed for researchers hunting automated crawler behavior.

The same technique surfaced long-running activity tied to OpenAI's infrastructure last year. It also caught traffic researchers linked to the recent Hugging Face episode.

In the new case, the URLquery trail pointed in two directions at once. Source IPs sat inside Tencent's address space. Destinations sat on Amap's directions endpoints.

Why does this case matter?

The Hugging Face incident pushed a handful of research groups to stand up persistent monitoring for rogue agent behavior. The Chinese case is the first public report to use that monitoring to flag a fleet operating against a major Chinese consumer service.

Three details stand out:

  • The agents made no effort to disguise themselves. They used standard HTTPS paths and ordinary API parameter names.
  • The operators did not appear to need messaging between agents to scale the workload. Adding more parallel jobs to the same endpoint was enough.
  • The target — Amap — exposes a high-resolution index of physical locations. A service that returns directions to every entrance of every zoo, park, and hospital in a city is a granular map of the built environment.

That last point carries weight beyond the immediate incident. Entrance-level routing data is useful feedstock for robotics, last-mile delivery logistics, accessibility tooling, and any navigation product that wants fine-grained guidance. The fact that a fleet of agents can build such an index by replaying an Amap query at scale turns a public consumer endpoint into an unsupervised scraping surface.

Common API defenses — rate limits, token-based authentication, captchas — assume the operator wants to stay roughly in compliance. The Tencent-linked fleet has no such constraint on the evidence so far.

How does this compare to past agent discoveries?

Researchers have used URLquery traffic to surface at least two earlier waves of AI-agent activity: one tied to OpenAI's infrastructure, and a separate wave linked to the Hugging Face incident. Both were flagged as long-running operations rather than one-off scrapes.

The Chinese case follows the same pattern. Traffic was sustained, not bursty. It ran across multiple parallel sessions from the same infrastructure block. And it hit the same kind of fine-grained location data for the duration of the observation window.

What is new is the geographic footprint. The previous public findings pointed at U.S.-headquartered AI labs. The Tencent-to-Amap path is the first widely shared dataset of an agent fleet operating entirely within Chinese infrastructure.

What do we still not know?

The report is short, and the researchers call it preliminary. Several core questions remain unanswered.

  • Who runs the agents. No operator has been named.
  • Which model powers them. No inference endpoint, prompt, or output has been captured.
  • What the scraped data is for. Venue categories suggest mapping, but robotics, surveillance, or commercial-intelligence motives cannot be ruled out.
  • How long the fleet has been active. The Sunday post is the first public record, but historical URLquery logs could extend the timeline back further.

Those gaps leave room for several scenarios. The fleet could be feeding a third-party mapping product, training a navigation model, populating a competitor to Amap, or assembling an internal business-intelligence dataset. None of those uses would require agents to coordinate beyond sharing a job description.

What happens next?

The researchers say they will publish more detail in the coming weeks. They are also reviewing historical URLquery logs to determine when Tencent-linked traffic first appeared.

Two downstream effects are worth watching. Alibaba, which operates Amap, has not commented on the report. If Amap's team decides to rate-limit entrance-level queries, the agent fleet would lose its main attack surface. And Tencent has not confirmed whether the flagged infrastructure belongs to a customer, a partner, or an internal team — a distinction that will shape any future attribution.

For now, the operative fact is simple. AI agents are running on the open web at scale, leaving fingerprints in services built to catch them, and the operators behind them are not yet trying very hard to hide.

Original: swarmcha.se

Share this article:

More from James Calloway

James Calloway

Show full bio

News editor covering industry trends and analytics at AI In Context.

223 articles

Related articles

  1. OpenAI agents hit UN trade site 16,000 times in three-month brute-force sweep
  2. One Israeli Startup Sits Behind a String of Rogue AI Disclosures
  3. Australia Says an OpenAI Agent Hacked a Government Health Site
  4. Anthropic Snubs Senate Hearing on AI and Datacentres
  5. OpenAI Agents Hit UN Trade API 16,500 Times via Google Game

« Previous article