// TOM'S HARDWARE US — HARDWARE & GADGET
AI agent fleet likely from Chinese firm Tencent pulled data from rival Alibaba’s maps, researchers say
Proxy name in the agents’ web traffic pointed to Tencent’s Hunyuan models.
When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.
A fleet of AI agents, likely using Tencent’s Hy models, has spent more than a week grabbing data from rival Alibaba’s Amap mapping service, says a preliminary report from the Swarmchasers. The fleet, which ran its code on Tencent Cloud behind a hysandbox-ats proxy, reached a peak of 1,810 URL query scans on Oct. 4 alone. The Swarmchasers, a group of researchers, also noted 211 scans labeled “claude,” a reference to Anthropic’s AI models, though the code behind them matches Chinese models, not Claude.
The free urlquery.net service works by opening a web address in a sandboxed remote browser, with a public record of the scan. It’s used to verify suspicious and risky links and also helps agents reach pages they otherwise would not be able to touch directly. Leveraging the service for this type of agent work is not new, as the nonprofit lab Transluce tied some urlquery activity to OpenAI’s agents last month. The fleet in question this time used similar techniques, but on new targets and infrastructure.
The event timeline began with a single Amap scan on Aug. 25, which the researchers don’t tie to the fleet. The fleet’s own scans started over a month later, on Sept. 28, and peaked on Sunday, with 1,810 of its 2,048 scans through Oct. 4 and 213 of its 216 target locations. That day, from four to eight runs were active at once, with a peak at 14, although that could have been a handful of fast agents, the researchers say. The fleet’s first scan was only three days after OpenAI’s disclosure of it having paused “all training, evaluation, and inference with tool-use” on its most capable models.
The agents sought information about user navigation, discovering what share of Amap users arrive at each entrance of places such as a park, museum, zoo, and hospital, with one location used per run; the researchers found no evidence on urlquery.net that the runs coordinated. At the Chengdu Zoo: North Gate 71%, East Gate 23%, Southeast Gate 6%. A separate place returned: ground car park 40%, main gate 26%, underground car park 11%, plus seven other entrances. The report doesn’t say what the data is for, but speculates that the pattern may be “an evaluation or task-generation run.”
To get around Amap’s protections, the agents relied on the generation of Alibaba anti-bot tokens and the borrowing of public API access keys, in addition to the routing. They also loaded Alibaba’s own Baxia anti-bot scripts, ran an agent-written Puppeteer function through the microlink API, and tried Baidu Translate’s page translator. The method of agent access suggests an intent to bypass the rules.
The agents’ programs sent their results to inboxes on webhook.site, whose public API shows the IP address and software that created each inbox, according to its open-source code. The researchers determined that 15 out of 16 readable Amap inboxes, from Oct. 4–5, were created from Tencent Cloud, 13 of them by a script rather than a person. The 16th came from Iraq and looked like a person rather than the fleet, the researchers said.
Nine requests from the agents’ own code reached the inboxes from Tencent Cloud in Hong Kong, each carrying a Via header ending “(hysandbox-ats).” A forwarding proxy will add that header to name itself, in this case Apache Traffic Server, under a name chosen by whoever runs it, so the report treats that name as self-reported. One marked request, for Ta’er Temple, only took one second to hit after the inbox was created, 35 seconds before its address appeared anywhere public, so only the environment that created the inbox could have known it.
Get Tom's Hardware's best news and in-depth reviews, straight to your inbox.