I'm not familiar with Win32 APIs. Could you elaborate more as to how they would enable you to control the client like a zombie?
I have actually done a lot of this, putting old sourceless win32 and win16 programs run in the background on virtual machines on the server and building new web-based interfaces on top of them.
Event spoofing is pretty limited. While having a thread under your control gives you full power as you have full access to the process' memory and can call any function you want.
In the same way applications use the win API to create their UI, others could use it to manipulate and control the interface of other programs. It's powerful.