A preliminary investigation by Swarmchasers describes repeated AI agent queries about the entrances people use to reach parks, museums, zoos and hospitals in China. The researchers traced public scanning records from September 28 through October 4 and found several runs working on different Amap places at the same time. They also found network traces pointing to Tencent Cloud infrastructure in Hong Kong. The records do not identify who assigned the task or why.

The big change

  • What changed: The researchers' public traces show a parallel agent task spread across many map locations. Their count reaches 216 places by October 4. Public scan records reveal only part of the activity.
  • Why it matters: A map service receiving such traffic can see repeated automated requests without knowing whether they came from one organization, an evaluation or another project. The distinction matters when operators investigate load and access patterns, and when readers see a cloud provider's name attached to an incident.
  • What to watch: The researchers say a full report will follow. Its ability to connect the visible queries to an operator, task and complete results will determine how far this case can be interpreted beyond the traffic record. The visible evidence already gives a narrower finding: similar requests ran in parallel, with no observed channel between the agents.

What the researchers recorded

Swarmchasers counted 2,048 Amap reports in its September 28 to October 4 dataset, including 1,810 on October 4. A report here is a record produced by urlquery, a service that fetches a submitted web address and publishes information about the resulting requests. The researchers counted 216 distinct Amap places. Their timing analysis suggests four to eight runs active at once for much of October 4, reaching a peak of 14. The report cautions that some apparent overlap could be a smaller number of fast agents.

Programs visible in the records sought Amap's figures for the share of users navigating to each entrance of a place. The report identifies two runs that read out entrance shares, including one for Chengdu Zoo. Many requests had an ambiguous outcome: even a response counted as successful by the scanner could be a CAPTCHA page. The report does not establish that every submission retrieved the desired figures.

The investigators' October 5 update says the last tagged Amap scan appeared at 04:11 UTC that day, with no later one in their data through 08:46 UTC. The observation covers visible tagged scans; the underlying task could have continued elsewhere.

What points to Tencent Cloud

The strongest link in the report's infrastructure evidence is a set of public inbox records. According to the researchers, 15 of 16 readable inboxes associated with Amap work on October 4 and 5 were created from Tencent Cloud addresses. Requests from the agents' code reached those inboxes from Tencent Cloud Hong Kong addresses and carried a proxy header named hysandbox-ats. In one example, the code contacted an inbox before its address appeared in the public scanning record, which supports the researchers' conclusion that the creator and sender were part of the same working environment.

That evidence connects the observed code to infrastructure. It does not establish who controlled the runs. Tencent Cloud can host other customers, and the report notes that a proxy name is self-reported. Some scan labels contained “claude,” but labels cannot identify the model. The researchers ran small model comparisons and argue that Tencent's Hy model is a better match; no record they found names the model or a training job.

Purpose and coordination remain open

The report describes many agents performing similar per-place work in parallel. Its authors found no inbox read-backs, shared channel, scan-to-scan links or results passed between places. They therefore use “fleet” for parallel activity and say they found no evidence of coordination. Similar tasks and copied programs alone do not show agents communicating with one another.

The purpose is equally uncertain. Repeated attempts on one place could fit an evaluation, task generation or another workflow, but the public records do not decide among them. The investigation shows queries for entrance-share information and two reported readouts. It provides no evidence of collection beyond the information sought in those queries. It does not prove a Tencent-directed operation, malicious intent or unlawful access.

For online service operators, the case illustrates how public agent traces can reveal volume and tactics while leaving accountability unresolved. For readers, the useful distinction is between a documented network path and a claim about who ordered the work. Swarmchasers' promised full report, or a statement from a party with direct knowledge, could narrow that gap.

Sources & further reading

  • Swarmchasers, “We found a Chinese agent fleet”, preliminary report dated October 4 and updated October 5, 2026. The original investigation supplies the counts, examples, network traces and stated limitations. Its findings are attributed here; BIG CHANGE did not reproduce the scan or inspect private logs.