Researchers Track an AI Agent Fleet on Tencent Infrastructure Targeting Alibaba’s Amap

Researchers say an AI agent fleet linked to Tencent infrastructure queried Alibaba’s Amap, highlighting new challenges in monitoring autonomous web activity.

AI News

Independent researchers say they have identified a persistent fleet of AI agents operating through infrastructure associated with Tencent and querying Alibaba’s Amap mapping service. The preliminary findings suggest multiple agents were requesting directions to entrances at public locations, including a park, zoo, and hospital.

The activity does not yet appear to show a coordinated attack or a sophisticated autonomous operation. Researchers described it as an “agent fleet” rather than a swarm because the agents appeared to work in parallel without communicating with one another. Even so, the discovery offers a concrete example of how AI systems can generate sustained traffic across the open web—and how difficult it can be to determine who is operating them and for what purpose.

What researchers observed

The researchers detected the activity by monitoring traffic associated with urlquery, a service that scans websites and records how pages respond. AI agents sometimes use services such as urlquery to access websites they cannot reach directly, creating an observable trail in the process.

According to the preliminary report cited by TechCrunch AI, the agents repeatedly queried Alibaba’s Amap service for directions to different entrances of public venues. The requests appear to have involved ordinary location lookups rather than content scraping, credential abuse, or an attempt to manipulate maps.

The infrastructure clues pointed toward Tencent, but the available evidence does not establish that Tencent operated, authorized, or even knew about the agents. Likewise, the requests to Amap do not by themselves identify the organization or individual behind the activity. The connection to China’s technology sector comes from the apparent involvement of Tencent infrastructure and Alibaba’s service, not from a disclosed operator identity.

The use of “fleet” is significant. A swarm normally implies coordination or communication among agents. In this case, the researchers reported many agents performing similar tasks independently, with no visible evidence that they were sharing information or following a central conversational protocol.

Evidence remains preliminary

The findings are based on internet observations rather than a public statement from Tencent, Alibaba, or the operator of the agents. TechCrunch reported that the research was still ongoing and that relatively few details were available. No source evidence provided an agent count, the model or models involved, the length of the operation, or the purpose of the location queries.

That limits what can responsibly be concluded. The activity may represent a deliberate effort to bypass Alibaba’s preferred access mechanisms, but researchers did not report evidence of a wider intrusion. TechCrunch characterized the behavior as apparently no more serious than sidestepping Amap’s API rules. That is an assessment of the observed requests, not a confirmed explanation from the operator.

The distinction matters for AI agents because web activity can look more threatening than it is—or less threatening than it may become. Automated requests sent through third-party infrastructure can obscure attribution, while repeated actions across many workers can create operational effects even when each individual query appears harmless.

The discovery also follows earlier incidents that prompted researchers to watch for rogue AI activity online, including the Hugging Face incident referenced in the report. Those investigations have benefited from a recurring weakness in current AI agents: they often rely on recognizable services and leave traces that conventional web monitoring can capture.

Why this matters for agent builders

For developers, the episode is a reminder that an AI agent is not confined to its model endpoint. Its behavior also depends on browsers, proxy services, web-access tools, cloud infrastructure, and external APIs. Each component can create logs, rate-limit events, or security signals that reveal the agent’s activity.

A system that launches many parallel workers needs more than a prompt-level safety policy. Builders should be able to identify which worker made a request, what task authorized it, which external service it contacted, and whether the action stayed within the service’s terms. Without that chain of accountability, a benign research workflow can resemble abuse, while an abusive workflow can be difficult to investigate.

The Amap queries also illustrate a practical reliability problem. Location services often expose multiple access paths, including websites, mobile interfaces, and formal developer APIs. An agent that uses a browser or a scanning intermediary to avoid an unavailable API may complete its task, but it can violate usage rules, produce excessive traffic, or undermine the service’s assumptions about user behavior.

For enterprises deploying AI agents, the relevant controls include outbound request logging, per-agent identity, limits on parallel activity, domain allowlists, and explicit approval for actions that touch third-party services. These measures do not prove that a system is safe, but they make unusual behavior easier to detect and explain.

What to watch next

The most important follow-up is whether researchers can identify the model, operator, or orchestration framework behind the fleet. Additional evidence could also clarify whether the agents were running continuously, how many workers were involved, and whether the requests were generated by one application or several unrelated systems.

Responses from Tencent and Alibaba would help establish whether their systems detected the activity, whether Tencent infrastructure was used by a customer or an unauthorized party, and whether Amap’s access controls were bypassed. It is also worth watching whether the requests stop after public disclosure or shift to other mapping and web services.

More broadly, researchers are likely to examine whether the same infrastructure patterns appear in other AI agent investigations. If agents repeatedly use urlquery and comparable services, those platforms could become valuable observation points for agent monitoring. But that visibility may not last if operators move to less transparent tooling or distribute requests across more providers.

Creati.ai perspective

This incident is less a story about a proven cyberattack than about the growing observability problem created by autonomous software. A collection of agents can generate meaningful internet activity without behaving like a coordinated swarm, and the difference matters for both risk assessment and response.

The immediate lesson for builders and enterprise buyers is operational: agent permissions, identity, and external-service access need to be designed together. Before expanding an agent’s autonomy, teams should be able to reconstruct its actions and distinguish authorized automation from traffic that merely happens to use the same infrastructure. The researchers’ preliminary findings show why that capability is becoming a baseline requirement, not an optional security feature.

Ads