AI NewsModels & agentsReported

Researchers tracked an agent fleet on Tencent Cloud that scanned Amap routes to parks, zoos and hospitals

Independent researchers at swarmcha.se said on 5 October that an agent fleet, likely running from Tencent Cloud in Hong Kong, has been using the public scanner urlquery to read Alibaba's Amap route data for parks, zoos and hospitals since 28 September.

AI News

Editorial3 min read

LinkedInX

Why it mattersA team shipping an agent that calls third-party services now has a public example of how outside researchers reconstruct the fleet's activity from the services it touches, so an operation that leaves records in public tools can be identified from those records alone.

An agent that calls somebody else's product leaves records in the services it touches, and those records are enough to identify the operator even when the operator does not log in. The researchers at swarmcha.se, who earlier reported on OpenAI's agents reading UNCTAD databases through a public scanner, posted a preliminary report on 5 October about a new agent fleet that has been reading Alibaba's Amap route data since 28 September, three days after OpenAI paused the tool use that produced its own scans. TechCrunch's Russell Brandom carried the finding later the same day.

What the researchers found

The report says the fleet reached its inboxes from a Tencent Cloud address in Hong Kong, through a proxy named hysandbox-ats, and that the agents' code matches Tencent's Hy4 and Zhipu GLM rather than Claude, even though 211 of the reports carried a "claude" label. The task was narrow: for each park, zoo, museum or hospital on a list, read what share of Amap users navigated to each entrance. 213 places had been read by the peak day of 4 October, from 1,810 reports in total. 4 to 8 agent runs were active at once that day, with a peak of 14, and 51 places were covered in the busiest hour.

The researchers resisted the word "swarm" for this activity. "'Agent fleet,' not 'swarm,'" one wrote, "many parallel agents on the same kind of task, with no sign of communication between them." No inbox was read back, no shared channel was found, and some programs were only copied between places after the earlier version had already appeared on urlquery, which the researchers took as a sign the agents saw each other through the public scanner rather than through a private link.

The 04:11 UTC pause, and what came next

The fleet's last tagged Amap scan was at 04:11 UTC on 5 October. 38 minutes earlier, at 03:33 UTC, a third party had posted a note into the fleet's own inbox 3b5027e4..., citing the researchers' post and telling the operator to rotate its infrastructure. The operator did rotate soon after, driven by its old webhook.site inbox hitting a 50-request cap. New inboxes appeared from Tencent Cloud addresses on 5 and 6 October, the first by python-requests/2.32.5 from the IP 43.162.199.79. New methods also appeared: pages hosted on catbox and bytebin, pushes through ntfy, and beacons to urlquery's own robots.txt.

How the researchers read the fleet's own records

The fleet's activity is visible because it uses urlquery, a public domain-scanning service, to load pages its own address cannot reach. The researchers monitored submissions to that service for every host under amap.com and gaode.com through 23:15 UTC on 4 October, matched the submission tags against the fleet's inbox IDs, and read the fleet's own HTML carriers (pages hosted on httpbin, httpbun and LiveCodes) that recorded the agents' prompts and sometimes the responses. The method is the same one that earlier revealed the long-running OpenAI scans TechCrunch covered in September.

Two consequences for a team shipping its own agent. Any public scanner, log aggregator or sandbox service the agent calls is readable by anyone who looks for the pattern, so a cheap monitoring strategy against your own agent is already in somebody else's data. And a response note sent to the fleet's inbox did nothing to stop the behaviour: a parallel fleet with no shared channel cannot be addressed by a message to one of its runs.

Source

This item was written by an AI system from the linked source. Reveneau is responsible for what it publishes.

Share
LinkedInX