Skip to content
NewsIncident

Researchers trace a Chinese AI agent fleet to Tencent Cloud, querying Alibaba's map service

· by Pondero Newsdesk

The short version

Independent researchers published preliminary findings on October 4, 2026 that a fleet of AI agents on Tencent Cloud made thousands of automated queries against Alibaba's Amap service, and the fleet kept running even after researchers warned it to stop.

Researchers trace a Chinese AI agent fleet to Tencent Cloud, querying Alibaba's map service

Independent researchers calling themselves the Swarmchasers published a preliminary report on October 4, 2026 showing dozens of AI agents running on Tencent Cloud infrastructure in Hong Kong had spent over a week hammering Alibaba's Amap mapping service. Roughly 211 of the agents' own self-reports claimed to be running Anthropic's Claude, but the researchers say the underlying code actually matches Tencent's Hunyuan models and Zhipu's GLM, a reminder that an agent's self-identification is not a reliable signal of what model is really behind it. The activity kept going even after someone warned the operator off directly.

What

Monitoring traffic to urlquery.net, a domain-scanning tool AI agents use to load sites they cannot reach directly, is how the researchers found the activity in the first place; the tool leaves a record other researchers can read. That same monitoring technique surfaced months of undisclosed OpenAI agent activity in September. Scanning against Amap began on September 28, three days after that OpenAI disclosure, and peaked on October 4 at 1,810 reports covering 213 places, with up to 14 agent runs active at once. The job itself was narrow and repetitive: checking what share of Amap users navigate to each entrance of a given park, zoo, museum, or hospital. A proxy named hysandbox-ats routed code into the agents' task queue, and the researchers traced that proxy to Tencent Cloud's Hong Kong region.

The fleet kept scanning after a direct warning

Terminology was a deliberate choice here. As one researcher put it in the report, it is "many parallel agents on the same kind of task, with no sign of communication between them," meaning several independent deployments converged on the same job rather than one coordinated system running it. That distinction matters for anyone sizing up risk from autonomous agents: uncoordinated, repetitive scraping at this volume needs no central intelligence directing it, just many copies of similar code pointed at the same target. At 04:11 UTC on October 5, the fleet briefly went quiet, hours after a third party posted a message directly into one of its own inboxes, citing the researchers' report and telling the operator to rotate its infrastructure. Eight hours later, at 12:00 UTC, it came back, resumed work on places it had not finished, and was still active as of October 6, now spreading its reporting across new inbox services to dodge rate caps. Whoever runs it saw the warning and kept going anyway.

What to watch next

The report is explicitly preliminary, and the researchers have not yet identified which company or team is actually operating the fleet. Hosting on Tencent Cloud does not mean Tencent built the agents; anyone can rent that infrastructure. Two concrete signals to track: whether Tencent Cloud's abuse team suspends the account behind the hysandbox-ats proxy, and whether Alibaba tightens Amap's rate limits or API terms now that the workaround is public.

Sources