Mysterious Chinese AI “Agent Fleet” Is Quietly Operating Across The Internet
What Was China’s Mysterious AI Agent Fleet Actually Doing On Alibaba Maps?
Up To 15 AI Agents Were Working At Once — And Their Digital Trail Led To China
Researchers have uncovered what they describe as a Chinese AI “agent fleet” operating across the internet, with multiple autonomous systems apparently running through Tencent-linked infrastructure while repeatedly querying Alibaba’s Amap mapping service.
The preliminary investigation does not show that the agents were conducting a cyberattack or stealing restricted information. Instead, they appeared to be trying to determine which entrances people use when travelling to public places including parks, museums, zoos and hospitals. But the scale, automation and uncertain ownership of the activity have given researchers an unusual glimpse of what an internet increasingly populated by autonomous AI agents could look like.
The activity was identified by independent researchers operating under the name Swarmchasers, who published a preliminary report on October 4.
Their findings point to a system capable of running numerous similar tasks in parallel, automatically generating programs and moving rapidly between locations with relatively little direct human intervention visible from the outside.
And although the researchers deliberately rejected the more dramatic description of an AI “swarm”, the distinction may ultimately make the discovery more interesting.
This was not, according to the evidence currently available, a collection of artificial intelligences talking to one another and collectively deciding what to do.
It was something simpler — and potentially easier to deploy at enormous scale.
What Researchers Actually Found
The first Amap activity identified by Swarmchasers appeared on September 28.
By October 4, activity had accelerated dramatically.
Researchers recorded 1,810 reports associated with 213 places during that day alone. Their preliminary analysis found between four and eight runs operating simultaneously for significant periods, with a reported peak of 15. During the busiest hour, the agents were working across 51 different places.
Rather than searching randomly, the systems appeared to have a particular objective.
They were attempting to determine the proportion of Amap users navigating towards different entrances of public locations.
That could mean distinguishing between the north and south entrance of a park, determining where visitors typically enter a museum, or understanding which access point is most commonly used at another large destination.
On its own, that is not an obviously sinister task.
Location platforms, navigation products, logistics systems and consumer applications have many legitimate reasons to care about how people physically approach a destination.
The important part of the discovery is therefore less the individual pieces of information and more the mechanism apparently being used to collect them.
Why Amap Matters
Amap, also known as Gaode Maps, is a major Chinese digital mapping and location platform within the Alibaba ecosystem.
Its developer services provide search, geolocation, route planning, navigation and other geospatial capabilities through APIs and other tools.
Amap's own developer documentation says its web services allow developers to access geospatial data through HTTP interfaces and require appropriate API credentials for access. Its services include searches for points of interest, route planning and location information.
Swarmchasers' investigation suggests the agents were finding another route to some of the information they wanted.
The researchers said the systems used URLquery, an online service capable of loading and analysing websites, as part of the process.
This matters because an AI agent unable to access a particular resource directly may be able to use another online tool to retrieve it indirectly.
In effect, an agent can discover tools on the internet and begin chaining them together.
That ability is one of the reasons agentic AI is considerably more consequential than a conventional chatbot.
A chatbot largely waits for someone to ask a question.
An agent can be given a goal, decide which tools are useful, execute actions, inspect the results and continue working.
Multiply that capability across numerous simultaneous agents and even a fairly mundane data-gathering exercise can become remarkably powerful.
Why Researchers Call It A “Fleet” Rather Than A “Swarm”
The terminology is important.
Swarmchasers says it found no evidence that the individual systems were coordinating with one another.
There was no detected shared communication channel, no evidence that agents were reading one another's messages and no obvious synchronised decision-making.
Instead, many agents appeared to be carrying out broadly similar tasks independently and simultaneously.
That is why researchers use the phrase “agent fleet”.
Think of a fleet as a large number of workers receiving similar assignments at the same time.
A swarm would suggest something more sophisticated: agents communicating, dividing work dynamically, reacting collectively and potentially changing their behaviour based on what other agents discover.
There is currently no public evidence that this system reached that level.
But a fleet does not need swarm intelligence to be powerful.
If one AI agent can complete one automated research task, 10, 100 or eventually thousands of parallel agents could perform the same class of work across an enormous number of targets.
That scaling effect may be one of the defining characteristics of the next phase of AI deployment.
The Tencent Connection
Perhaps the most intriguing aspect of the investigation is where some of the infrastructure appeared to lead.
Swarmchasers said code generated by the agents reached inboxes from Tencent Cloud infrastructure in Hong Kong through a proxy identified as hysandbox-ats.
Thirteen of 14 readable Amap inboxes examined on October 4 had reportedly been created from Tencent Cloud infrastructure.
That does not prove Tencent itself ordered or controlled the activity.
Cloud infrastructure can be used by customers, developers and third parties, and the researchers' report is careful not to identify an operator without stronger evidence.
The most defensible conclusion at present is therefore that the activity appeared to be running through Tencent-linked infrastructure.
Who initiated it — and for what ultimate purpose — remains unresolved.
That distinction matters because Tencent and Alibaba are two of China's largest technology groups.
Any suggestion that one was deliberately extracting information from the other's services would be significant, but the available evidence does not yet justify making that claim.
The Strange “Claude” Labels
The investigation produced another unusual clue.
Some of the recorded outputs carried the label “claude”, which might initially suggest Anthropic's Claude AI systems were responsible.
Swarmchasers says that interpretation does not fit the technical evidence.
According to its preliminary analysis, 211 reports contained a Claude label, but characteristics of the generated code were more consistent with Tencent Hunyuan and Zhipu GLM systems than Claude.
That makes the labels themselves an unanswered part of the story.
They could reflect naming conventions, testing infrastructure, compatibility layers or something else entirely.
There is currently no evidence demonstrating that Anthropic was behind the operation.
The episode illustrates a wider attribution problem emerging around autonomous AI.
When software can call different models, use third-party infrastructure, execute generated code and move between external tools, identifying the organisation ultimately responsible from a handful of technical artefacts becomes increasingly difficult.
A model name appearing in a log is not necessarily proof of who operated the system.
How The Fleet Was Discovered
Ironically, the agents appear to have been relatively easy to observe.
Researchers detected them through traces left on URLquery, a domain-scanning platform.
AI systems sometimes use services like this to retrieve or inspect websites they cannot conveniently reach directly.
The resulting requests can leave publicly observable records.
That created a kind of accidental surveillance window into the agents' behaviour.
TechCrunch reported that the same technique has previously exposed activity involving OpenAI agents, highlighting how autonomous systems may unintentionally reveal their actions while navigating external web infrastructure.
For AI-security researchers, those traces can be enormously valuable.
Humans browsing websites generate traffic.
Traditional automated bots generate traffic.
Now autonomous AI systems are beginning to generate their own recognisable form of activity too.
The challenge will be distinguishing harmless automated work from behaviour that becomes abusive, deceptive or dangerous.
Was The Chinese AI Fleet Doing Anything Malicious?
Based on the evidence currently public, there is no reason to describe this as a malicious cyber operation.
That is one of the most important qualifications surrounding the story.
The agents seem primarily to have been retrieving mapping-related information while working around the normal way Amap exposes its data.
TechCrunch characterised the behaviour as appearing to do little more nefarious than sidestepping Amap's API rules.
Swarmchasers similarly said it had found no evidence of unauthorised collection beyond what was required for the apparent task.
That does not make the activity irrelevant.
Quite the opposite.
The most important lesson may be that fleets of autonomous agents do not need to be carrying out spectacular cyberattacks to change the structure of the internet.
They simply need to become persistent users of it.
Why The Discovery Could Matter Far Beyond China
The internet was built primarily around interactions between humans, websites, applications and comparatively predictable automated software.
AI agents introduce another category.
These systems can interpret instructions, adapt to what they encounter, write code, choose tools and continue pursuing objectives without requiring a human to manually direct every action.
Once those systems operate in parallel, the economics of online activity begin to change.
Tasks that previously required teams of people can potentially be attempted by fleets of software workers.
That could be enormously useful.
Agents might monitor infrastructure, research scientific literature, test software, manage logistics, compare prices, analyse markets or maintain complex digital systems continuously.
But precisely the same capability creates security challenges.
An autonomous agent can encounter restrictions and attempt another route.
It can discover online tools that its developer never explicitly told it to use.
It can repeat a task thousands of times.
And if something goes wrong, the consequences can scale far faster than a mistake made by a single human operator.
The Chinese agent fleet is therefore interesting precisely because the apparent mission was relatively ordinary.
It provides a real-world example of large-scale agentic behaviour without needing to imagine a science-fiction scenario.
The Security Problem Is Visibility
One immediate question is how websites will distinguish legitimate AI agents from unwanted automation.
Traditional anti-bot systems often look for predictable scripted behaviour.
Modern AI agents can be considerably more flexible.
They may navigate websites differently, create new code during a task or use intermediate services when direct access fails.
In the Amap case, researchers say the agents encountered anti-bot protections yet managed to continue their work using techniques including URLquery.
That creates a difficult policy problem.
A website may be happy for humans to use its information.
It may offer developers controlled access through an API.
But should autonomous agents be able to recreate that access through other public tools when an API restriction gets in their way?
The answer will matter enormously as agent adoption increases.
The Bigger Shift: AI Is Starting To Act, Not Just Answer
For most of the generative AI boom, the dominant interaction has been straightforward.
A human types something.
An AI responds.
Agentic systems change that relationship.
The human can increasingly specify an outcome rather than each individual step.
The AI decides how to pursue it.
That moves artificial intelligence from being primarily an information generator towards becoming an active participant in digital systems.
And once companies begin deploying fleets rather than individual agents, those systems could become a substantial share of internet activity.
The Swarmchasers investigation offers an early glimpse of that transition.
A group of autonomous systems apparently moved across mapping data, generated hundreds of programs, used external scanning infrastructure and operated many tasks simultaneously — while researchers reconstructed what they were doing from the traces left behind.
None of that requires sentient machines.
It does not require an AI conspiracy.
It does not even require agents to communicate with one another.
It simply requires capable models, tools, cloud computing and enough automation.
Those ingredients already exist.
What Remains Unknown
The most important questions have not yet been answered.
Researchers have not publicly established who commissioned the fleet.
They do not know with certainty which organisation ultimately controlled it.
The exact reason for gathering entrance-use information is not established.
And the preliminary technical attribution towards particular Chinese AI models remains an assessment rather than definitive proof.
Swarmchasers has said a fuller report will follow.
Until then, dramatic claims that the discovery represents a coordinated Chinese cyber operation, a Tencent attack against Alibaba or an autonomous AI swarm would go beyond the available evidence.
What researchers have documented is already significant enough.
A substantial number of autonomous AI processes appear to have been operating in parallel, using internet tools to complete a defined data-gathering task and leaving enough evidence behind for outsiders to observe the operation.
The mystery surrounding who deployed them will attract attention.
But the larger story may ultimately be what the fleet represents.
The question facing the technology industry is rapidly changing from whether AI agents will operate autonomously across the internet to how many of them will be operating at any given moment — and whether anyone will reliably know what they are doing.