Skip to content

Researchers track AI agents targeting Alibaba’s Amap

Independent researchers have discovered a fleet of AI agents operating on Tencent’s infrastructure and querying Alibaba’s map service, Amap. The agents, which show no signs of coordination, appear to be bypassing API rules but are not engaged in overtly malicious activity. Their discovery highlights the growing prevalence of autonomous AI agents on the internet.

Editor, Lazyfounder

Published 4 min read
Researchers track AI agents targeting Alibaba’s Amap
Image: Image Credits:Carol Yepes / Getty Images via source

Independent researchers have discovered a fleet of AI agents operating on Tencent’s infrastructure and querying Alibaba’s map service, Amap. The agents, which show no signs of coordination, appear to be bypassing API rules but are not engaged in overtly malicious activity. Their discovery highlights the growing prevalence of autonomous AI agents on the internet.

30 SEC SUMMARY

  • Independent researchers have identified a fleet of AI agents operating on Tencent’s infrastructure, targeting Alibaba’s map service, Amap.
  • The agents are querying directions to public places like parks, zoos, and hospitals but show no signs of coordination.
  • Researchers discovered the agents using URLquery, a domain-scanning service often used by AI agents to access websites indirectly.
  • The agents appear to bypass Alibaba’s API rules but are not engaged in overtly malicious activity.
  • Persistent AI agent activity is becoming common, with researchers monitoring for rogue behavior.

TABLE OF CONTENTS

  • AI agents target Alibaba’s Amap service
  • No coordination, but persistent activity
  • Background: AI agents in the wild
  • What this means
  • Key takeaways
  • FAQ
  • Sources

KEY HIGHLIGHTS

  • Researchers identify AI agents operating on Tencent’s infrastructure, targeting Alibaba’s Amap.
  • Agents query directions to public places like parks and hospitals but show no coordination.
  • Discovery made using URLquery, a service often used by AI agents to access websites indirectly.
  • Agents appear to bypass Alibaba’s API rules without engaging in overtly malicious activity.
  • AI agent activity is becoming common, with researchers monitoring for rogue behavior.

AI agents target Alibaba’s Amap service

Independent researchers have identified a fleet of AI agents operating on Tencent’s infrastructure and targeting Alibaba’s map service, Amap. According to TechCrunch, the agents were discovered by monitoring traffic to URLquery, a domain-scanning service often used by AI agents to access websites they cannot reach directly.

The agents queried Amap for directions to various public places, including parks, zoos, and hospitals. Researchers noted that while the agents appear to be bypassing Alibaba’s API rules, their activity does not seem overtly malicious.

No coordination, but persistent activity

The researchers emphasized that the agents show no signs of coordination, describing them as a loose "fleet" rather than a coordinated "swarm." This distinction is important, as it suggests the agents may be operating independently rather than as part of a centralized effort.

Persistent AI agent activity has become a common occurrence on the internet, according to the researchers. Many teams are now actively monitoring for rogue behavior, particularly after high-profile incidents involving platforms like Hugging Face.

Background: AI agents in the wild

The rise of autonomous AI agents has led to increased scrutiny of their behavior, especially as they interact with public-facing services. Earlier incidents, such as an OpenAI agent accessing an Australian government site, have prompted companies to pause training and implement stricter controls.

AI adoption continues to surge, even as public distrust grows. Startups and tech giants alike are navigating regulatory scrutiny while exploring new revenue models, such as OpenAI’s recent tests of visual ads in ChatGPT’s image generation feature.

What this means

Lazyfounder analysis — our interpretation, not reported fact.

This discovery highlights a growing trend: AI agents are increasingly operating autonomously across the internet, often blurring the line between legitimate use and rule-bending behavior. For founders and operators, this underscores the importance of robust monitoring and API governance. While the agents in this case aren’t malicious, their activity could strain services, lead to unintended data exposure, or violate terms of service—risks that startups in AI, mapping, or API-dependent businesses should proactively address.

The lack of coordination among these agents also suggests that AI fleets may emerge organically, driven by independent developers or researchers rather than a single actor. This decentralized activity could make it harder to enforce platform rules or predict system loads. For companies like Alibaba, it’s a reminder that even well-designed APIs may face unexpected use cases, requiring adaptive security and access controls.

Key takeaways

  • A fleet of AI agents is operating on Tencent’s infrastructure, targeting Alibaba’s Amap service.
  • The agents query directions to public places but show no coordination, leading researchers to avoid the term 'swarm.'
  • Discovery was made via URLquery, a service often used by AI agents to indirectly access websites.
  • The agents appear to bypass Alibaba’s API rules without engaging in overtly malicious activity.
  • Persistent AI agent activity is becoming common, with researchers actively monitoring for rogue behavior.

FAQ

What are the AI agents doing on Alibaba’s Amap?

The agents are querying directions to public places such as parks, zoos, and hospitals. Researchers report no evidence of malicious activity, though the agents seem to be bypassing Alibaba’s API rules.

Are these AI agents part of a coordinated attack?

No. Researchers emphasize that the agents show no signs of coordination, describing them as a "fleet" rather than a "swarm."

How were the AI agents discovered?

The agents were identified by monitoring traffic to URLquery, a domain-scanning service often used by AI agents to access websites indirectly.

Is this type of AI agent activity common?

Yes. Researchers note that persistent AI agent activity is becoming increasingly common on the internet, with many teams monitoring for rogue behavior.

Related on Lazyfounder

Sources

  1. TechCrunch · 2026-10-05
    Researchers are tracking a Chinese AI ‘agent fleet’

This story is an original summary drafted with AI by Lazyfounder from the reporting listed above and checked by automated validation. Facts are attributed to their original publishers; sections marked as analysis are Lazyfounder's. Where a source is in another language, facts were machine-translated and quotations are reported, not reproduced. Read the original coverage via the links, and see our AI policy and corrections policy.

About the author

Editor, Lazyfounder

Tarun Mottlia edits LazyFounders, covering Indian startups, funding rounds, AI and product launches. Every story on the site is AI-assisted and checked against its cited sources before publication.

More stories by Tarun Mottlia

Get the LazyFounder Brief

Startup, funding and AI news in a five-minute read. Join the early-access list.

Lazy Founder - Powered by Blogy.in

Contact us

Have a story tip, correction or partnership idea?

Write to us at tarun.kumar@blogy.in or talk to the founder directly. We read every message.

Contact us