\n\n\n\n Somebody's Robot Army Really Wants to Know Where the Zoo Entrance Is - AgntHQ \n

Somebody’s Robot Army Really Wants to Know Where the Zoo Entrance Is

📖 4 min read•800 words•Updated Oct 5, 2026

Picture a researcher on a Sunday afternoon, coffee going cold, staring at traffic logs for URLquery — a domain-scanning service most people have never heard of and have no reason to care about. It’s the kind of tool AI agents reach for when they want to load a website they can’t get to directly. And on this particular afternoon, the logs are busy. Not botnet-scraping-the-whole-internet busy. Something stranger. Over and over, requests are flowing toward Amap, Alibaba’s mapping service, asking the same narrow category of question: how do I get to the entrance?

Not the entrance of a bank. Not a data center. Parks. Zoos. Hospitals.

That’s the finding a group of independent researchers posted preliminarily on Sunday, with BizToc and TechCrunch picking it up Monday. The fleet appears to be running on Tencent’s infrastructure, pointed at Alibaba’s map product, and — this is the part that stuck with me — the agents seem to run in parallel with no communication between them. Many hands, no group chat.

What we actually know versus what everyone wants it to mean

I review AI tools for a living, which means I spend a lot of time watching people take four data points and build a conspiracy theory on top of them. So let me be boring about the facts, because the facts are genuinely limited and the research is still ongoing.

  • A large number of AI agents were spotted via traffic to URLquery.
  • They appear to be hosted on Tencent infrastructure.
  • They query Amap, Alibaba’s mapping service.
  • They want directions to entrances of public places — parks, zoos, hospitals.
  • They don’t appear to talk to each other.

That’s it. No attribution to a company, a team, or a purpose. No stated goal. No confirmed scale beyond “fleet.” Anyone telling you they know what this is for is telling you a story, not a finding. I’m not going to do that, and you should be suspicious of outlets that do.

The boring explanations are the most likely ones

Here’s where I’ll put my own read on the table, clearly labeled as opinion. The most probable explanations for weird agent behavior are almost always mundane, and they usually come down to someone’s evaluation pipeline running wild.

If you’ve ever built an agent benchmark, you know the pattern. You need a task that has a verifiable answer, requires a tool call, and can be generated in volume. “Find the entrance to this public place” is close to perfect for that. The answer is checkable. The query is repeatable. The variations are endless, because there are a lot of parks. And if you’re spinning up thousands of isolated test runs, each in its own sandbox, you’d get exactly what the researchers describe — parallel workers with no awareness of each other, hammering the same service.

The other plausible read is data collection for a navigation or last-meter routing model. Entrance locations are notoriously messy in map data. A park might have six gates and one of them is the only one open on weekdays. That’s expensive, annoying information to compile by hand and a reasonable thing to farm out to agents.

Neither of those is confirmed. Both are more likely than the version where this is espionage, and I say that having read the separate reporting on actual Chinese-speaking operators running a sustained espionage campaign tracked as GTG-10007. Real state-adjacent misuse of AI exists and is documented. That doesn’t make every cluster of odd traffic an instance of it. Pattern-matching on nationality instead of behavior is how you get bad analysis.

The part that should actually change how you think

Forget whodunit for a second. The durable lesson here is about volume.

Agents are now a persistent, measurable share of internet traffic, and they behave nothing like human users. They don’t get bored. They don’t rate-limit themselves out of politeness. They route around blocks by piping requests through intermediary services, which is precisely why URLquery became the observation window in the first place. A tool built to inspect suspicious domains turned into a telescope pointed at the agent population.

If you run any kind of public API or data service, this is your problem now, not a story about two Chinese tech giants. Someone’s test use can become your traffic spike. Your analytics are measuring machines and calling them visitors. Your abuse heuristics were tuned for humans clicking too fast, not for ten thousand isolated workers each behaving perfectly reasonably on their own.

And notice who caught this. Not Tencent. Not Alibaba. Not a vendor dashboard. A handful of independent researchers reading logs on a Sunday. The infrastructure for understanding what agents are doing out there is currently a few curious people and a domain-scanning service. That’s the gap worth closing, whatever this particular fleet turns out to be looking for.

🕒 Published:

📊
Written by Jake Chen

AI technology analyst covering agent platforms since 2021. Tested 40+ agent frameworks. Regular contributor to AI industry publications.

Learn more →
Browse Topics: Advanced AI Agents | Advanced Techniques | AI Agent Basics | AI Agent Tools | AI Agent Tutorials
Scroll to Top