Skip to content
TECH STARTUP & BUSINESS NEWS

Researchers are tracking a Chinese AI ‘agent fleet’

The preliminary findings, published by a group of independent researchers on Sunday, shed light on the evolving nature of automated web activity. According to the report, these AI agents have been actively working with Chinese map data, routing their operations through Tencent’s network architecture while focusing their queries on Amap, Alibaba’s prominent map and navigation service.

While the term "swarm" has frequently been used in recent months to describe coordinated groups of automated AI programs, the researchers leading this latest investigation are pushing back against that label. They argue that the term implies a level of synchronization and collective intelligence that is absent in this current deployment. Instead, they prefer the designation "agent fleet."

Elaborating on this distinction in their preliminary report, one of the researchers noted that the observation points to "many parallel agents on the same kind of task, with no sign of communication between them." Rather than acting as a cohesive, communicative hive mind, these digital entities appear to be operating independently while executing similar sets of instructions simultaneously.

The discovery of the agent fleet was not made through traditional cybersecurity defense software, but rather by monitoring traffic routed through URLquery, a public domain-scanning and website-testing service. This investigative technique has proven increasingly valuable to the security and research communities. Just weeks prior, a similar monitoring approach revealed long-running, extensive activity by OpenAI agents probing online databases for obscure facts.

AI agents frequently utilize services like URLquery to load and interact with websites that they might otherwise struggle to access directly due to structural barriers or technical limitations. This reliance on intermediary scanning tools inadvertently leaves a comprehensive digital paper trail, recording the timestamps, IP addresses, and specific targets of the automated queries. For independent researchers tracking the proliferation of automated web traffic, these logs have become a primary window into the hidden operations of modern language models and autonomous programs.

Researchers are tracking a Chinese AI ‘agent fleet’

An examination of the URLquery logs associated with this latest Tencent-hosted infrastructure revealed a specific pattern of behavior. The agents were systematically issuing queries to Alibaba’s Amap service, seeking detailed directions to various specific entrances of prominent public locations. Among the targets identified in the preliminary data were public parks, municipal zoos, and medical facilities. By querying multiple entry points for these destinations, the automated agents were effectively gathering granular geographic and logistical data regarding how to enter and navigate these physical spaces.

Because the research remains in its early stages and investigation is ongoing, many technical details regarding the exact scope and purpose of the operation remain unavailable. However, the emergence of this fleet highlights the sheer persistence and ubiquity of AI agent activity across the modern internet. Autonomous programs are no longer confined to controlled laboratory environments or specialized enterprise platforms; they are actively roaming the public web on a massive scale, performing complex, multi-step tasks without human intervention.

This latest discovery arrives at a time of heightened sensitivity within the cybersecurity and tech research communities regarding autonomous digital entities. In the wake of high-profile security incidents, such as the Hugging Face breach earlier this year, security analysts and independent researchers have stepped up their vigilance. Many are actively monitoring the digital landscape for rogue or unauthorized agent activity that could pose security risks or violate terms of service agreements.

Much of this automated activity has proven relatively easy to locate and analyze. Because many developers rely on standardized frameworks and deployment techniques, AI agents frequently leave distinct behavioral signatures and make little serious effort to conceal their digital identities or infrastructure origins.

In the case of this newly discovered fleet targeting Alibaba’s Amap, the observed actions appear relatively benign. The researchers emphasize that the agents do not seem to have been engaged in malicious cyberattacks, data theft, or destructive behavior. Instead, their actions appear to be focused on side-stepping Alibaba’s official Application Programming Interface (API) rules and data retrieval limitations. By querying mapping data through alternative pathways rather than utilizing official, rate-limited developer channels, the operators of the fleet were able to harvest location data at scale.

Nevertheless, security experts caution that while this particular instance may represent a relatively harmless workaround of corporate API restrictions, the broader trend carries significant implications. The capability to deploy massive fleets of parallel, automated agents to scour public-facing services demonstrates a powerful toolset that can easily be repurposed. As autonomous agent technology continues to mature and proliferate, researchers warn that the internet may not always be dealing with actors as benign as those behind the current Tencent-hosted mapping queries.

Leave a Reply

Your email address will not be published. Required fields are marked *