Technology

A Fleet of AI Agents Was Spotted Querying a Chinese Map Service

Martin HollowayPublished 5m ago3 min readBased on 2 sources
Reading level
A Fleet of AI Agents Was Spotted Querying a Chinese Map Service
Photo by Tima Miroshnichenko on Pexels

Independent researchers posted preliminary findings on Oct. 5, 2026 about a fleet of AI agents that appears to run on Tencent's infrastructure and query Alibaba's map service Amap. TechCrunch

The disclosure is preliminary, not a finalized incident report.

The fleet was found by monitoring traffic to URLquery, a domain-scanning service that records what addresses automated visitors request. Urlquery.net was identified as the scanner referenced in Transluce's disclosure. researchers' first-hand report

URLquery records showed the agents asking Amap for directions to different entrances of public places, including a park, a zoo, and a hospital. The queries were narrow and task-specific. No coordination was observed.

The researchers described the activity as "agent fleet, not swarm," meaning many parallel agents doing the same kind of task with no sign of communication between them. The telemetry, the raw tracking data, is public.

Attribution in the first-hand report is also qualified. The fleet was described as likely originating from Tencent Hy, and the researchers' account titled 'We found a Chinese agent fleet' is published at swarmcha.se.

For practitioners following agent deployments, the fleet versus swarm wording carries the practical lesson. Parallelism without messages between agents points toward replicated single-agent rollouts rather than a coordinated multi-agent system with shared state or delegation, where agents divide work and share memory. That simpler setup is easier to deploy at scale and easier to observe, because each copy leaves a similar trace on the same external API.

Looking at what this means for detection work, scanner telemetry remains a useful vantage point. Agents that browse or call public services leave egress trails, outbound signals, that URL scanners, sandboxes, and passive DNS infrastructure can see, even when the model backend and orchestration layer stay hidden. In this case, the entrance-seeking navigation queries formed a recognizable behavioral cluster.

The broader context here is that infrastructure attribution remains thin on its own. Running on a given cloud does not by itself identify an operator, and the current material stops at a likely-origin assessment tied to Tencent Hy. Entrance-level directions queries are also ambiguous by nature. They exercise planning, tool use, and grounding against real-world constraints without revealing a downstream application.

In my view, the right way to treat this disclosure is as an early observational data point for production agent behavior outside controlled evals. The sample is small, three categories of public place, and the task is routine. Its value is not the task itself but the pattern, many independent instances doing similar tool-mediated work in parallel, caught through third-party scan data rather than vendor logging.