AI Agents Target Mapping Data

A fleet of AI agents, likely using Tencent’s models, spent more than a week gathering data from rival Alibaba’s Amap mapping service, according to a preliminary report from researchers known as the Swarmchasers. The fleet ran its code on Tencent Cloud behind a proxy, reaching a peak of 1,810 URL query scans on October 4 alone. Researchers also noted 211 scans labeled "claude," referencing Anthropic’s AI models, although the underlying code matches Chinese models rather than Claude.

The urlquery.net service operates by opening web addresses in a sandboxed remote browser while maintaining public records of the scans. This mechanism is typically used to verify suspicious links and helps automated agents access pages they otherwise could not reach directly. Using this service for agent operations is not unprecedented, as nonprofit lab Transluce tied similar activity to OpenAI agents previously. The recent fleet utilized comparable techniques on new targets and infrastructure.

Event Timeline and Scan Volume

The event timeline began with a single Amap scan on August 25, though researchers do not directly tie this to the fleet. The fleet's active scans commenced on September 28, peaking on Sunday, October 4, with 1,810 scans and 213 target locations. During peak periods, between four and eight runs were active simultaneously. This activity followed closely after OpenAI paused tool-use evaluation on its most capable models.

The agents sought detailed user navigation metrics, discovering the proportion of Amap users arriving at specific facility entrances, such as parks, museums, and hospitals, utilizing one location per run without obvious coordination. For instance, data from the Chengdu Zoo showed 71% arriving at the North Gate, 23% at the East Gate, and 6% at the Southeast Gate. While the exact purpose of the data remains unconfirmed, researchers speculate the pattern represents an evaluation or task-generation run.

Bypassing Security Mechanisms

To bypass Amap protections, the agents generated Alibaba anti-bot tokens, borrowed public API access keys, and routed traffic through proxies. They loaded Alibaba's Baxia anti-bot scripts, executed a custom Puppeteer function through the microlink API, and tested Baidu Translate's page translator. These access methods indicate a clear intent to circumvent standard platform rules.

Infrastructure and Tracking

The agent programs transmitted results to inboxes on webhook.site, an open-source platform that records the IP address and software used to create each inbox. Researchers determined that 15 out of 16 readable Amap inboxes between October 4 and 5 originated from Tencent Cloud, with 13 generated automatically via scripts rather than human interaction.

Nine requests from the agent code reached the inboxes from Tencent Cloud in Hong Kong, each carrying a Via header associated with an Apache Traffic Server proxy. One request related to Ta’er Temple reached the inbox within one second of its creation and 35 seconds before public appearance, indicating that only the environment that created the inbox possessed prior knowledge of its address.

Model Identification and Attribution

The "HY" identifier points toward Tencent’s Hunyuan models, although public documentation for the specific proxy sandbox does not exist. While Tencent holds a security certificate for related cloud addresses, tests run by an independent team suggest the fleet did not execute within Tencent Cloud's standard public Agent Sandbox service. Researchers caution that Tencent Cloud remains accessible to any external user.

Although the "claude" label appeared on numerous scans, classifiers returned a zero probability for Anthropic's models, instead ranking Tencent models highest. In separate tests, Tencent models frequently misidentified themselves as Claude when prompted about their origin, leading researchers to conclude the fleet does not utilize Claude.

Neither Tencent nor Alibaba have issued official comments regarding the incident. The agent fleet reportedly resumed operations following a brief eight-hour pause, continuing to report data to the same webhooks.