← Back to Blog
Agentic AI

Tracking the Chinese Agent Fleet: What Multi-Agent Swarms Mean for Global Agentic AI Architecture

October 6, 2026
Armor Tech
9 min read
Tracking the Chinese Agent Fleet: What Multi-Agent Swarms Mean for Global Agentic AI Architecture

Independent researchers have identified a persistent fleet of AI agents operating on Tencent infrastructure and systematically querying Alibaba's Amap service for routing data. The agents operate in parallel without inter-agent coordination — a distinction the research team emphasizes by using "fleet" rather than "swarm." This discovery, made through passive monitoring of the urlquery scanning service, reveals how visible autonomous agent traffic has become when operators neglect basic operational security.

Detection Methodology: urlquery as a Side Channel

The research team discovered the fleet by monitoring urlquery.net, a public URL scanning service that renders submitted links in a sandboxed browser. AI agents that cannot directly access certain endpoints — due to bot detection, geographic restrictions, or authentication requirements — frequently offload page loads to urlquery. Each submission leaves a timestamped record: the target URL, the user agent string, the referring infrastructure, and the rendered DOM.

This same technique previously exposed months of OpenAI agent activity targeting obscure databases. In both cases, the agents made no effort to rotate infrastructure, vary user agents, or avoid known monitoring points. The urlquery submissions created an unintentional audit trail.

For the Chinese fleet, the urlquery logs showed repeated submissions targeting amap.com endpoints with direction-request parameters: origin/destination pairs corresponding to specific entrances of parks, zoos, and hospitals across multiple Chinese cities. The referring IP blocks resolved to Tencent Cloud ASNs. The user agent strings were generic Chrome/Headless signatures with no custom identifiers.

Fleet vs. Swarm: A Meaningful Architectural Distinction

The researchers' terminology choice reflects a real architectural difference. A swarm implies emergent coordination: agents share state, negotiate task allocation, or adapt collectively to feedback. A fleet describes multiple independent agents executing the same policy in parallel — essentially horizontal scaling without a control plane.

In this case, each agent appears to receive a discrete query (e.g., "directions from north gate to east gate of People's Park, Shanghai") and executes it independently. There is no evidence of:

  • Shared memory or message passing between agents
  • Dynamic task rebalancing when individual agents fail
  • Collective decision-making about which targets to query next
  • Leader election or coordinator nodes

This matters for detection and mitigation. A swarm can adapt its behavior when individual nodes are blocked — redistributing work, changing query patterns, or going dormant. A fleet simply continues until each unit is individually throttled or the operator intervenes. The lack of coordination also means the fleet generates more detectable noise: N agents making similar requests from similar infrastructure is statistically trivial to cluster.

Target Selection: Why Amap?

Alibaba's Amap (高德地图) is the dominant mapping and navigation platform in China, with extensive POI data, real-time traffic, and detailed entrance/exit metadata for major venues. The fleet's queries focus specifically on entrance-level routing — not city-to-city navigation, but "gate A to gate B" within a single facility.

This suggests a data collection objective rather than real-time navigation. Possible motivations:

  • Training data for a competing geospatial model: Entrance-level routing graphs are valuable for last-mile logistics, autonomous delivery, or AR navigation — areas where high-fidelity Chinese map data is scarce outside the Alibaba/Tencent duopoly.
  • API limit evasion: Amap's public API imposes strict daily quotas and per-second rate limits. A fleet of agents scraping the web frontend bypasses these controls entirely.
  • Competitive intelligence: Systematic coverage of venue entrances across cities could map Amap's POI completeness and routing accuracy relative to Tencent's own map product.

None of these are inherently malicious, but all violate Amap's terms of service. The fleet's scale — hundreds of parallel agents over sustained periods — imposes non-trivial load on Alibaba's infrastructure.

Infrastructure Attribution: Tencent Cloud

The urlquery submissions originated from IP ranges allocated to Tencent Cloud (ASN 45090, 38803, and associated blocks). This does not necessarily mean Tencent operates the fleet — the infrastructure could be rented by a third party, compromised, or used by an internal team without centralized oversight. However, the consistency of the infrastructure across weeks of activity suggests intentional provisioning rather than opportunistic compromise.

Tencent has invested heavily in foundation models (Hunyuan) and agent frameworks. Running large-scale data collection on their own cloud would be operationally convenient: no egress fees, direct access to GPU clusters for any downstream processing, and simplified networking. The question is whether this represents a sanctioned product initiative, a research project, or unauthorized use by a team with cloud credits.

Alibaba and Tencent have a long history of competitive friction across payments, cloud, social, and now AI. An agent fleet targeting a core Alibaba asset from Tencent infrastructure fits a pattern of asymmetric data warfare that has characterized the Chinese tech sector for a decade.

Operational Security Failures

The fleet's detectability stems from elementary OPSEC failures:

Failure Observation Mitigation (Not Used)
Static infrastructure Same Tencent Cloud IP blocks for weeks Residential proxy rotation, multi-cloud distribution
Generic fingerprints Headless Chrome user agents, no canvas/WebGL spoofing Realistic browser profiles, fingerprint randomization
Public side-channel All urlquery submissions visible to any researcher Private rendering farms, headless browsers on controlled infra
Predictable query patterns Sequential entrance-pair enumeration per venue Jittered scheduling, randomized target ordering
No authentication masking Direct queries to public Amap endpoints Session hijacking, token rotation, authenticated scraping

These are not sophisticated oversights. They are the default behavior of prototype agent code deployed without a red-team review. The same failures appeared in the OpenAI agent activity documented last month — suggesting that even well-resourced labs treat agent deployment as a software engineering problem rather than an operational one.

Post-Hugging Face Monitoring Landscape

The research community's detection capability has improved significantly since the Hugging Face incident, where compromised credentials led to unauthorized model access and data exfiltration. That event catalyzed systematic monitoring of:

  • Public scanning services (urlquery, urlscan.io, Hybrid Analysis)
  • Certificate transparency logs for new agent-related domains
  • Passive DNS for C2 infrastructure patterns
  • Honeypot endpoints seeded in common agent target lists

The Chinese fleet was caught because it intersected with the first monitoring vector. A more careful operator would render pages locally, use residential proxies, and never touch a public sandbox. That the fleet didn't suggests either arrogance, incompetence, or a calculated decision that the data value outweighs the exposure risk.

Implications for API Providers

For services like Amap, this fleet represents a new class of abuse: not credential stuffing or DDoS, but structured data extraction at scale via autonomous agents. Traditional defenses fail:

  • Rate limiting by IP: Tencent Cloud has thousands of exit IPs; the fleet rotates naturally.
  • CAPTCHA: Modern agents solve CAPTCHAs via vision models or third-party solving APIs.
  • User agent blocking: Trivial to rotate.
  • Behavioral analysis: Individual agents look like legitimate users making a few requests. The fleet nature only emerges in aggregate.

Effective mitigation requires graph-level detection: correlating request patterns across IP blocks, identifying shared latent features (timing, parameter ordering, header structure), and attributing to operator infrastructure. This is significantly more expensive than per-request filtering and requires dedicated threat intelligence teams.

Some providers are experimenting with poisoned data — returning subtly incorrect routing for detected scrapers — but this risks degrading experience for legitimate users caught in false positives. Others are moving toward authenticated APIs with cryptographic proof-of-work, effectively raising the cost of unauthenticated access above the agent operator's budget.

Geopolitical Context: AI Competition Within China

This fleet operates in a specific regulatory and competitive environment. China's AI governance framework requires algorithm filing for deployed models, data localization for user data, and security assessments for models with "public opinion attributes." An agent fleet scraping a competitor's map data likely falls into multiple regulatory gray zones.

However, the Chinese tech giants have historically operated with significant autonomy in data collection, provided they don't cross political red lines. Tencent and Alibaba both maintain massive mapping datasets collected through their super-apps (WeChat, Alipay) and dedicated map products. The competitive pressure to improve foundation models with proprietary geospatial data is intense — and the regulatory framework for how that data is acquired remains ambiguous.

Internationally, this mirrors the broader pattern: US labs (OpenAI, Anthropic, Google) deploy agents that scrape aggressively; Chinese labs do the same. The difference is visibility. The US activity was caught via the same urlquery vector. The Chinese fleet was caught the same way. In both cases, the operators — presumably sophisticated — failed basic OPSEC. This suggests a systemic gap: agent frameworks make deployment easy, but don't include operational tradecraft by default.

Technical Lessons for Agent Operators

If you are deploying agents at scale, the Chinese fleet offers a negative case study:

  1. Never use public sandboxes. Build or rent private rendering infrastructure. The marginal cost is trivial compared to the intelligence leakage.
  2. Infrastructure hygiene is part of the agent loop. IP rotation, fingerprint management, and request jittering should be baked into the agent runtime, not bolted on afterward.
  3. Assume monitoring. urlquery is one of dozens of passive collection points. Certificate transparency, passive DNS, BGP monitoring, and honeypot networks all create attribution risk.
  4. Coordinate or don't. A fleet is easier to detect than a single agent but harder to mitigate than a swarm. Choose your architecture based on threat model, not convenience.
  5. Data exfiltration channels matter. How does the agent get results back? If it's writing to a shared bucket, that bucket is a detection target. If it's returning via the same channel, that traffic is observable.

None of these are novel. They're standard operational security applied to a new deployment paradigm. The gap is organizational: ML teams build agents; security teams secure infrastructure; rarely do they collaborate before production deployment.

Frequently Asked Questions

Is this fleet definitively operated by Tencent?

The traffic originates from Tencent Cloud IP blocks, but attribution to Tencent as an organization is not proven. The infrastructure could be rented by a third party, used by an internal team without formal approval, or compromised. The consistency and duration suggest intentional provisioning, but the operator's identity remains unconfirmed.

What makes this a "fleet" rather than a "swarm"?

A swarm implies inter-agent coordination: shared state, task negotiation, collective adaptation. The observed agents operate independently — each executes a discrete query without communicating with peers. They share infrastructure and target selection logic, but no runtime coordination mechanism has been detected.

Could this activity be legitimate research?

Legitimate academic or commercial research typically uses authenticated APIs, respects robots.txt and rate limits, and identifies itself via user agent strings. This fleet uses none of those practices. It systematically evades API controls via web frontend scraping, hides behind generic headless browser signatures, and makes no effort to identify its operator. These are not the markers of authorized research.

The Chinese agent fleet is a symptom of a broader shift: autonomous agents are becoming a persistent, visible layer of internet traffic. Their operators — whether corporate labs, state actors, or freelance scrapers — are learning operational security the hard way. For defenders, the lesson is clear: agent traffic leaves fingerprints at every layer from infrastructure to behavior. The teams that instrument for those fingerprints will see the next fleet before it scales.

Related reading