Totally agreed on motivations of attackers.
One reason why I think talking about malicious actors makes sense is that in some scenarios you will have actors who unwittingly help the attacker. Their expected range of behaviour is part of the threat model, so they should be mentioned somehow while being distinguished from the attackers (who are unconstrained in their range of behaviour save for things they can't do).
@robryk absolutely! I really like scenarios with multiple actors such as a phisher and an internal employee for just that reason