{"slug": "researchers-trace-amap-querying-agents-code-to-tencent-cloud", "title": "Researchers trace Amap-querying agents' code to Tencent Cloud", "summary": "Independent researchers at Swarmchasers reported in a preliminary report dated October 4th that AI agents queried Alibaba's Amap mapping service through activity associated with Tencent Cloud infrastructure in Hong Kong, tallying 2,048 Amap-related reports covering 216 places from September 28th through October 4th, including 1,810 reports across 213 places on October 4th alone. The report, whose lead authors are Alecto Irene Perez and Ethan Elasky with Rowan Howard-Jones as corresponding author, says the agents' code more closely resembled Tencent Hy4 and Zhipu GLM than Anthropic's Claude despite 211 reports carrying a \"claude\" label, and does not identify who launched the agents. The researchers call the activity an \"agent fleet\" rather than a swarm because they found no sign the parallel runs communicated or coordinated, and the evidence does not establish a Tencent operation, data theft, or an attack directed by Alibaba.", "body_md": "# Researchers trace Amap-querying agents' code to Tencent Cloud\n\n**Swarmchasers found parallel agents probing Amap for venue-entrance data, with infrastructure evidence pointing to Tencent Cloud but not proving who deployed them.**\n\n        By [Ryan Merket](https://runtimewire.com/author/ryan-merket)\n        · Published \n\nPrimary source: [TechCrunch](https://techcrunch.com/2026/10/05/researchers-are-tracking-a-chinese-ai-agent-fleet/)\n\n## Why it matters\n\nA public trail can reveal what agents query and which infrastructure they use, but those clues do not identify an operator. The distinction is central as companies deploy agents that can route around ordinary web-access limits.\n\nIndependent researchers at Swarmchasers reported in a [preliminary report dated October 4th and updated the next morning](https://swarmcha.se/posts/chinese-agent-fleet?ref=runtimewire) that AI agents had queried Alibaba's Amap mapping service through activity associated with Tencent Cloud. The report describes parallel runs asking which entrances visitors use at parks, museums, zoos and hospitals. It does not identify who launched them. [TechCrunch also covered the findings on October 5th](https://techcrunch.com/2026/10/05/researchers-are-tracking-a-chinese-ai-agent-fleet/?ref=runtimewire).\n\nThe researchers call the activity an \"agent fleet,\" not a swarm: they found agents pursuing similar tasks but no sign the runs communicated or coordinated. That distinction keeps the evidence in proportion. The investigation documents persistent automated queries and apparent efforts to work around Amap's usual API restrictions. It does not establish a Tencent operation, a data theft, or an attack directed by Alibaba.\n\n### The trail runs through public scanning records\n\nThe Swarmchasers report lists Alecto Irene Perez and Ethan Elasky as lead authors and Rowan Howard-Jones as corresponding author. The researchers found the activity in public records from URLquery, a domain-scanning service that can load a website on a user's behalf. The service has also exposed earlier agent activity: [Transluce documented agents using URLquery to access public data sources](https://transluce.org/agent-activity?ref=runtimewire), and [TechCrunch reported on that investigation](https://techcrunch.com/2026/09/25/for-months-openais-agent-swarms-have-been-attacking-online-databases-to-find-obscure-facts/?ref=runtimewire).\n\nSwarmchasers' report says the fleet's first Amap-related scans appeared on September 28th, with activity rising sharply on October 4th. Its [preliminary tally](https://swarmcha.se/posts/chinese-agent-fleet?ref=runtimewire) lists 2,048 Amap-related reports and 216 places from September 28th through October 4th; 1,810 reports covered 213 places on October 4th alone. Those are counts of observed reports, not a count of distinct agents or people. The researchers also recorded as many as 14 simultaneous runs and 51 places queried during the busiest hour.\n\nThe traffic pattern raised a second question: what system produced the code? The researchers say the agents' code reached disposable inboxes through a proxy called `hysandbox-ats` from Tencent Cloud infrastructure in Hong Kong. They also found that the code more closely resembled Tencent Hy4 and Zhipu GLM than Anthropic's Claude, despite 211 reports carrying a \"claude\" label. That is the researchers' technical inference, not confirmation from Tencent, Zhipu or Anthropic. A cloud provider's infrastructure can show where traffic passed; it does not, by itself, show who controlled the workload or whether the provider knew about it.\n\nTencent has a direct commercial connection to AI infrastructure: [Tencent Cloud](https://www.tencentcloud.com/?ref=runtimewire) sells cloud and AI services, and RuntimeWire previously examined [Tencent's Hy4 model and its benchmark performance](https://runtimewire.com/article/tencent-hy4-preview-vals-open-weight-agent-cost). That context makes the researchers' model comparison relevant, but it cannot turn a resemblance into attribution. The evidence currently supports a narrower conclusion: some observed code and infrastructure appear consistent with Tencent-linked systems.\n\n### A question of access, not proven theft\n\nThe agents' apparent task was to estimate the share of Amap users navigating to different entrances at public venues. Swarmchasers reported that two runs read out entrance shares. The available findings do not establish that the agents obtained personal location histories, accessed private accounts or extracted a user-level dataset. The stated concern is that they may have used URLquery to get around Amap's ordinary API limits.\n\nHigh-volume, automated lookups can raise access questions even when they concern public places. The report describes code being repeated across runs and a high volume of requests; it does not show a shared command channel or a centrally directed campaign. \"Fleet\" is a useful description of parallel activity, not proof of an organization behind it.\n\nFor Tencent, the stakes are attribution and control. Its infrastructure appears in the trail, and Tencent-related models are part of the researchers' technical comparison. Neither observation establishes that Tencent deployed the agents. For Alibaba, the immediate issue is automated querying of its map service and possible circumvention of API rules; the findings do not show a broader compromise of Alibaba systems.\n\nThe investigators' work also shows why these incidents can be hard to classify. Public URL-scanning services leave records that outside researchers can inspect, while the agent's operator may remain unidentified. In this case, the logs offer a meaningful view of what the software asked and how it reached the service. They leave the key accountability question open: who set the task, and what limits - if any - governed the agents as they pursued it?", "url": "https://wpnews.pro/news/researchers-trace-amap-querying-agents-code-to-tencent-cloud", "canonical_source": "https://runtimewire.com/article/researchers-track-ai-agents-amap-tencent-cloud", "published_at": "2026-10-06 23:41:48+00:00", "updated_at": "2026-10-06 23:48:41.173934+00:00", "lang": "en", "topics": ["ai-agents", "artificial-intelligence", "ai-safety"], "entities": ["Swarmchasers", "Amap", "Alibaba", "Tencent Cloud", "Tencent Hy4", "Zhipu GLM", "Anthropic Claude", "URLquery"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/researchers-trace-amap-querying-agents-code-to-tencent-cloud", "markdown": "https://wpnews.pro/news/researchers-trace-amap-querying-agents-code-to-tencent-cloud.md", "text": "https://wpnews.pro/news/researchers-trace-amap-querying-agents-code-to-tencent-cloud.txt", "jsonld": "https://wpnews.pro/news/researchers-trace-amap-querying-agents-code-to-tencent-cloud.jsonld"}}