Independent researchers have identified a fleet of artificial intelligence agents operating on Tencent’s infrastructure while querying Alibaba’s Amap mapping service. These parallel agents requested directions to specific entrances at public venues such as a park, a zoo, and a hospital without communicating with one another. The discovery relied on monitoring traffic to URLquery, a domain-scanning tool that logs requests made by agents unable to access websites directly. This incident follows recent concerns about rogue activity, including the Hugging Face breach, prompting teams to watch for similar unauthorised behaviour online.
The behaviour highlights how persistent these systems have become in bypassing API restrictions, even when their actions appear benign. While the current agents only sidestepped rules to gather location data, similar techniques could be used for more damaging purposes in the future. Researchers note that the lack of concealment makes detection easier but also suggests the technology is maturing rapidly.




