Researchers Track Tencent AI Agent Fleet on Alibaba Maps
Independent researchers have discovered a fleet of AI agents running on Tencent infrastructure that is scraping Alibaba's mapping service, highlighting the rise of uncoordinated bot activity.

Independent researchers have identified a coordinated yet uncommunicative group of AI agents operating on Tencent's cloud infrastructure. This "agent fleet," as the researchers have designated it, has been actively querying Amap, a digital mapping and navigation service owned by Alibaba. The activity was uncovered through the systematic monitoring of urlquery, a domain-scanning service that AI agents frequently use to bypass direct access restrictions on target websites.
By analyzing the public logs left on urlquery, investigators traced a series of parallel queries directed at Amap. The automated agents were specifically requesting directions to various entrances of public venues, including a zoo, a hospital, and a local park. Because there was no evidence of communication or coordination between the individual queries, researchers explicitly avoided calling the activity a "swarm," opting instead for the term "agent fleet" to describe the parallel but isolated tasks.
This discovery comes amid heightened vigilance within the cybersecurity and AI research communities. Following a security incident at Hugging Face, analysts have stepped up their efforts to track rogue or unauthorized agent activity across the internet. Many of these automated systems are relatively easy to detect because they rely on predictable, repetitive techniques and make little effort to mask their digital footprints. In this specific instance, the Tencent-based agents appeared to be executing a workaround to bypass Alibaba's standard API limitations rather than conducting a malicious cyberattack.
For AI developers and system administrators, this development underscores the necessity of robust traffic monitoring and API rate-limiting. As autonomous agents become more pervasive, organizations must anticipate non-human traffic that attempts to circumvent traditional access controls via third-party proxy services like urlquery. Understanding these scraping patterns will help practitioners design better defensive measures to protect proprietary data and maintain service stability against automated harvesting.
This is our own summary of reporting by TechCrunch AI



