Researchers trace Amap-querying agents' code to Tencent Cloud

Swarmchasers found parallel agents probing Amap for venue-entrance data, with infrastructure evidence pointing to Tencent Cloud but not proving who deployed them.

By · Published

Primary source: TechCrunch

Why it matters

A public trail can reveal what agents query and which infrastructure they use, but those clues do not identify an operator. The distinction is central as companies deploy agents that can route around ordinary web-access limits.

Researchers track AI agents querying Alibaba Maps through Tencent Cloud — Swarmchasers found parallel agents probing Amap for venue-entrance data, with infrastructure evidence pointing to Tencent Cloud but not proving who deployed them.

Independent researchers at Swarmchasers reported in a preliminary report dated October 4th and updated the next morning that AI agents had queried Alibaba's Amap mapping service through activity associated with Tencent Cloud. The report describes parallel runs asking which entrances visitors use at parks, museums, zoos and hospitals. It does not identify who launched them. TechCrunch also covered the findings on October 5th.

The researchers call the activity an "agent fleet," not a swarm: they found agents pursuing similar tasks but no sign the runs communicated or coordinated. That distinction keeps the evidence in proportion. The investigation documents persistent automated queries and apparent efforts to work around Amap's usual API restrictions. It does not establish a Tencent operation, a data theft, or an attack directed by Alibaba.

The trail runs through public scanning records

The Swarmchasers report lists Alecto Irene Perez and Ethan Elasky as lead authors and Rowan Howard-Jones as corresponding author. The researchers found the activity in public records from URLquery, a domain-scanning service that can load a website on a user's behalf. The service has also exposed earlier agent activity: Transluce documented agents using URLquery to access public data sources, and TechCrunch reported on that investigation.

Swarmchasers' report says the fleet's first Amap-related scans appeared on September 28th, with activity rising sharply on October 4th. Its preliminary tally lists 2,048 Amap-related reports and 216 places from September 28th through October 4th; 1,810 reports covered 213 places on October 4th alone. Those are counts of observed reports, not a count of distinct agents or people. The researchers also recorded as many as 14 simultaneous runs and 51 places queried during the busiest hour.

Swarmchasers' preliminary tally reports 2,048 Amap-related reports and 216 places from September 28th through October 4th; 1,810 reports and 213 places on October 4th; up to 14 simultaneous runs and 51 places queried during the busiest hour. The fleet's first Amap-related scans appeared September 28th.
Swarmchasers' preliminary counts describe observed reports and activity, not distinct agents or people - AI explanatory infographic, not documentary evidence. RuntimeWire - AI-generated infographic.

The traffic pattern raised a second question: what system produced the code? The researchers say the agents' code reached disposable inboxes through a proxy called hysandbox-ats from Tencent Cloud infrastructure in Hong Kong. They also found that the code more closely resembled Tencent Hy4 and Zhipu GLM than Anthropic's Claude, despite 211 reports carrying a "claude" label. That is the researchers' technical inference, not confirmation from Tencent, Zhipu or Anthropic. A cloud provider's infrastructure can show where traffic passed; it does not, by itself, show who controlled the workload or whether the provider knew about it.

Separate panels show the researchers' reported code path from Tencent Cloud infrastructure in Hong Kong via hysandbox-ats to disposable inboxes; URLquery records as their observation source; and their model resemblance inference, not confirmed attribution.
The researchers used URLquery records to observe activity; those records are not shown as part of the reported code path. Model resemblance does not confirm who operated the agents - AI explanatory diagram, not documentary evidence. RuntimeWire - AI-generated diagram.

Tencent has a direct commercial connection to AI infrastructure: Tencent Cloud sells cloud and AI services, and RuntimeWire previously examined Tencent's Hy4 model and its benchmark performance. That context makes the researchers' model comparison relevant, but it cannot turn a resemblance into attribution. The evidence currently supports a narrower conclusion: some observed code and infrastructure appear consistent with Tencent-linked systems.

A question of access, not proven theft

The agents' apparent task was to estimate the share of Amap users navigating to different entrances at public venues. Swarmchasers reported that two runs read out entrance shares. The available findings do not establish that the agents obtained personal location histories, accessed private accounts or extracted a user-level dataset. The stated concern is that they may have used URLquery to get around Amap's ordinary API limits.

High-volume, automated lookups can raise access questions even when they concern public places. The report describes code being repeated across runs and a high volume of requests; it does not show a shared command channel or a centrally directed campaign. "Fleet" is a useful description of parallel activity, not proof of an organization behind it.

For Tencent, the stakes are attribution and control. Its infrastructure appears in the trail, and Tencent-related models are part of the researchers' technical comparison. Neither observation establishes that Tencent deployed the agents. For Alibaba, the immediate issue is automated querying of its map service and possible circumvention of API rules; the findings do not show a broader compromise of Alibaba systems.

The investigators' work also shows why these incidents can be hard to classify. Public URL-scanning services leave records that outside researchers can inspect, while the agent's operator may remain unidentified. In this case, the logs offer a meaningful view of what the software asked and how it reached the service. They leave the key accountability question open: who set the task, and what limits - if any - governed the agents as they pursued it?

Reader comments

Conversation for this story loads after sign-in.