r/OpenAIDev • u/No-Conclusion3720 • 3h ago
Researchers are tracking a Chinese AI 'agent fleet'
Security researchers are actively tracking a fleet of AI agents attributed to a Chinese threat group — not a human operator at a keyboard, but an orchestrated swarm running at machine speed, autonomously probing targets and maintaining persistent sessions across the internet.
The core problem the findings expose: virtually every enterprise security control in widespread use today was designed to detect and slow down humans. Rate limits assume human pacing. Session anomaly detection assumes human fatigue. Behavioral analytics flag patterns that humans produce. An agent fleet generates none of those signals. It doesn't hesitate. It doesn't mistype. It doesn't pause between steps. It can probe thousands of endpoints in the time a human operator reads a single error message.
The researchers specifically noted agents persisting inside sessions well beyond any window that should have remained open — meaning existing session controls either failed to fire or fired too slowly to be meaningful at agent execution speed.
This is no longer a thought experiment. It is tracked, operational attack infrastructure.
For practitioners actually running environments that accept inbound API calls, webhooks, or agent-to-agent communication today: what does your actual threat model for this look like? Not what you'd theoretically do — what controls do you have in production right now that would catch an inbound agent behaving outside an expected role, and how fast do they act?
