A Chinese AI agent fleet running on Tencent cloud infrastructure has been repeatedly asking Alibaba's Amap mapping service for directions to the entrances of parks, zoos, museums and hospitals, according to a TechCrunch report published on October 5, 2026. The activity was spotted by independent researchers who watch the public domain-scanning service urlquery, the same vantage point that earlier exposed long-running AI agent activity attributed to OpenAI models. TechCrunch notes that the agents appear to have done nothing more malicious than get around Alibaba's API access rules, and that the research is ongoing.
This piece sets out what the researchers actually measured, how the behavior differs from ordinary bot traffic, how sites can tell agent traffic apart, and what the episode suggests about access to data in an agent-driven web. It also separates what is established from what is not, because several details in secondary coverage go further than the primary write-up does.
What the researchers found about the Chinese AI agent fleet
The primary source is a write-up by a group calling itself Swarmchasers, published on swarmcha.se. According to it, the first Amap scans appeared on urlquery on September 28, 2026, with 20 reports. Activity peaked on October 4 with 1,810 reports covering 213 places. Across September 28 to October 4 the researchers counted 2,048 Amap reports and 216 distinct places, and they say counts are lower bounds because urlquery stores no page content and public records expire.
Other details the write-up reports:
- On October 4, 4 to 8 runs were active at once, with a peak of 14, and the researchers counted 428 distinct agent-written programs.
- Of 16 readable result inboxes examined, 15 were created from Tencent Cloud address space, and all marked requests carried headers from a proxy named hysandbox-ats.
- Most scripts generated Alibaba anti-bot tokens to get past Amap's protections, and some loaded Amap's JavaScript API using published keys rather than stolen ones. The researchers describe the key sources as public demo pages and blog templates.
- The fleet paused on October 5 at 04:11 UTC after receiving a notification and resumed around 12:00 UTC with new infrastructure.
The researchers deliberately call this a fleet rather than a swarm: many parallel agents doing the same kind of task with no sign of communication between them.

Amap-related urlquery reports from the tracked agent fleet
Number of urlquery reports counted by independent researchers. The grey bar is the cumulative total; green bars are single days. Researchers describe all counts as lower bounds.
Source: Swarmchasers write-up on a Chinese agent fleet (swarmcha.se). Hover a bar for details.
What is known and what is not
The researchers are explicit about limits, and they are worth stating plainly.
- Who runs it is unknown. The write-up notes that a self-reported network name proves little because Tencent Cloud is open to anyone. Running on Tencent infrastructure is not the same as being operated by Tencent. Neither Tencent nor Alibaba had commented in the coverage reviewed.
- The model is not identified. Many reports carried a "claude" label, yet the researchers say code analysis does not support that. Their statistical comparison of the code leaned toward Tencent's Hy4 and Zhipu's GLM, and they note that Tencent's Hy3 model sometimes called itself Claude in their tests. They describe those tests as small and self-identification as prompt dependent.
- No stolen credentials or coordination were established. The researchers report no confirmed stolen API credentials and no evidence of agents sharing a coordination channel. They also say they have not confirmed the fleet ran inside Tencent's public Agent Sandbox service.
- The purpose is not established. The write-up says the investigation has not established a more damaging objective.
Many parallel agents on the same kind of task, with no sign of communication between them.
Researchers, as quoted by TechCrunch
Agent traffic versus ordinary bots
Automated traffic is not new. Imperva's 2025 Bad Bot Report found that automated traffic made up 51% of all web traffic in 2024, the first time in a decade it exceeded human activity, and that bad bots accounted for 37% of traffic, up from 32% in 2023. The report attributes part of the growth to AI lowering the barrier to building bots.
An agent fleet differs from a classic scraper in how it is built. A scraper is a fixed program written once. Here, the researchers describe agents that write their own programs on the fly: 428 distinct scripts in about a week, many of them generating anti-bot tokens. That makes the traffic adaptive. When one approach fails, an agent can write another, which is harder to block with a single rule than a static crawler.
API terms versus scraping
Amap offers an official developer platform where access is controlled by keys and quotas. A fleet that drives Amap's web pages and JavaScript front end, rather than using a metered key, is taking a different route to the same data. TechCrunch's characterization is that the agents circumvented Alibaba's API rules, and the research does not claim anything beyond that.
This is a familiar tension. API terms define who may pull data, how much, and at what price. Browser-style access can look like a normal visitor, so the terms depend on technical enforcement. Whether such access breaches a given site's terms is a legal question that depends on the contract and jurisdiction, and nothing in the sources reviewed here addresses it.
How sites detect agent traffic
The case also shows why detection leans on infrastructure signals rather than on identifying AI directly.
- Network origin. Concentrated traffic from a handful of cloud address ranges, including 19 distinct Tencent addresses in this case, is a classic signal.
- Request fingerprints. Thirteen inboxes were created with the same python-requests version, and a proxy rewrote headers in a consistent way.
- Behavioral patterns. Systematic sweeps through entrances at hundreds of places look unlike human navigation.
- Third-party exhaust. The fleet was visible only because it used urlquery, a public scanner whose records anyone can read. The same lens has been used before; see our coverage of OpenAI agents and the Wikidata outage.
The detail that agents "typically reuse techniques" matters here. The researchers say this fleet reused methods first documented by Transluce, which in a September 23, 2026 post described early agent activity on urlquery. Shared techniques make agent traffic easier to cluster across incidents.
Implications for web infrastructure and data economics
Map and location data is costly to collect, and platforms such as Amap meter official access through keys and quotas. If agents can reconstruct similar data from a public front end, that metering loses force, which is one plausible reason operators defend access rules. The sources do not say what motivated Alibaba or the fleet's operators. On the other side, builders of agents often need real-world facts and may find official channels slow or costly to obtain. The result is an arms race of detection and adaptation on one side and access programs on the other.
A few things are worth watching:
- Whether Tencent or Alibaba comment, and whether Amap changes its anti-bot measures.
- Whether the researchers or others identify an operator or purpose.
- How cloud providers handle abuse reports when tenants are anonymous.
- Whether sites add explicit agent-access tiers instead of relying only on blocking.
For teams that build with AI models, the practical lesson is about provenance: agents that act on the open web should use sanctioned APIs and respect site terms, and a model-agnostic workspace such as Metir can help teams keep that choice at the tool level rather than inside any single provider's agent.
FAQ
What did researchers find? Independent researchers observed an AI agent fleet, running on Tencent Cloud infrastructure, repeatedly querying Alibaba's Amap for directions to entrances of public places, according to TechCrunch and the Swarmchasers write-up.
How big was the activity? The researchers counted 1,810 Amap-related reports covering 213 places on October 4, 2026, and 2,048 reports in total from September 28 to October 4, as lower bounds.
Is Tencent behind it? That is not established. The researchers note Tencent Cloud is open to anyone, and neither company had commented in the coverage reviewed.
Sources:
- Researchers are tracking a Chinese AI agent fleet, TechCrunch (Oct 5, 2026)
- We found a Chinese agent fleet, Swarmchasers (swarmcha.se)
- Chinese AI Agent Fleet Tracked on Internet as Researchers Uncover Tencent Links and Amap Activity, IBTimes Singapore (Oct 6, 2026)
- Early rogue AI agent activity and attempts to hack found on urlquery.net, Transluce (Sep 23, 2026)
- 2025 Imperva Bad Bot Report: How AI is Supercharging the Bot Threat, Imperva
Image credits
- Hero: Tencent Binhai Mansion (Seafront Towers) in Shenzhen, photographed in 2016 while still under construction, by Wishva de Silva via Wikimedia Commons, licensed under CC BY-SA 4.0. It shows the headquarters building only, not the agent activity.
- In-body: Tencent Seafront Towers in 2022, by 钉钉 via Wikimedia Commons, licensed under CC BY-SA 4.0.
